Sep 4 01:15:42.773079 kernel: Linux version 6.12.108-flatcar (build@pony-truck.infra.kinvolk.io) (x86_64-cros-linux-gnu-gcc (Gentoo Hardened 14.3.1_p20250801 p4) 14.3.1 20250801, GNU ld (Gentoo 2.45 p3) 2.45.0) #1 SMP PREEMPT_DYNAMIC Thu Sep 3 22:51:27 -00 2026 Sep 4 01:15:42.773108 kernel: Command line: BOOT_IMAGE=/flatcar/vmlinuz-a mount.usr=/dev/mapper/usr verity.usr=PARTUUID=7130c94a-213a-4e5a-8e26-6cce9662f132 rootflags=rw mount.usrflags=ro consoleblank=0 root=LABEL=ROOT console=tty1 console=ttyS0,115200n8 earlyprintk=ttyS0,115200 flatcar.first_boot=detected flatcar.oem.id=azure flatcar.autologin verity.usrhash=0655b4a97b09474b54b9e087df655bcd3d8c009e1539ef38d6f8e422c98586a7 Sep 4 01:15:42.773120 kernel: BIOS-provided physical RAM map: Sep 4 01:15:42.773127 kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009ffff] usable Sep 4 01:15:42.773134 kernel: BIOS-e820: [mem 0x00000000000c0000-0x00000000000fffff] reserved Sep 4 01:15:42.773141 kernel: BIOS-e820: [mem 0x0000000000100000-0x00000000044fdfff] usable Sep 4 01:15:42.773149 kernel: BIOS-e820: [mem 0x00000000044fe000-0x00000000048fdfff] reserved Sep 4 01:15:42.773156 kernel: BIOS-e820: [mem 0x00000000048fe000-0x000000003ff1efff] usable Sep 4 01:15:42.773163 kernel: BIOS-e820: [mem 0x000000003ff1f000-0x000000003ffc8fff] reserved Sep 4 01:15:42.773172 kernel: BIOS-e820: [mem 0x000000003ffc9000-0x000000003fffafff] ACPI data Sep 4 01:15:42.773179 kernel: BIOS-e820: [mem 0x000000003fffb000-0x000000003fffefff] ACPI NVS Sep 4 01:15:42.773185 kernel: BIOS-e820: [mem 0x000000003ffff000-0x000000003fffffff] usable Sep 4 01:15:42.773192 kernel: BIOS-e820: [mem 0x0000000100000000-0x00000002bfffffff] usable Sep 4 01:15:42.773199 kernel: printk: legacy bootconsole [earlyser0] enabled Sep 4 01:15:42.773207 kernel: NX (Execute Disable) protection: active Sep 4 01:15:42.773216 kernel: APIC: Static calls initialized Sep 4 01:15:42.773223 kernel: efi: EFI v2.7 by Microsoft Sep 4 01:15:42.773231 kernel: efi: ACPI=0x3fffa000 ACPI 2.0=0x3fffa014 SMBIOS=0x3ff88000 SMBIOS 3.0=0x3ff86000 MEMATTR=0x3e984698 RNG=0x3ffd2018 Sep 4 01:15:42.773238 kernel: random: crng init done Sep 4 01:15:42.773244 kernel: secureboot: Secure boot disabled Sep 4 01:15:42.773251 kernel: SMBIOS 3.1.0 present. Sep 4 01:15:42.773257 kernel: DMI: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 04/22/2026 Sep 4 01:15:42.773263 kernel: DMI: Memory slots populated: 2/2 Sep 4 01:15:42.773269 kernel: Hypervisor detected: Microsoft Hyper-V Sep 4 01:15:42.773275 kernel: Hyper-V: privilege flags low 0xae7f, high 0x3b8030, hints 0x9e4e24, misc 0xe0bed7b2 Sep 4 01:15:42.773283 kernel: Hyper-V: Nested features: 0x3e0101 Sep 4 01:15:42.773290 kernel: Hyper-V: LAPIC Timer Frequency: 0x30d40 Sep 4 01:15:42.773296 kernel: Hyper-V: Using hypercall for remote TLB flush Sep 4 01:15:42.773303 kernel: clocksource: hyperv_clocksource_tsc_page: mask: 0xffffffffffffffff max_cycles: 0x24e6a1710, max_idle_ns: 440795202120 ns Sep 4 01:15:42.773316 kernel: clocksource: hyperv_clocksource_msr: mask: 0xffffffffffffffff max_cycles: 0x24e6a1710, max_idle_ns: 440795202120 ns Sep 4 01:15:42.773437 kernel: tsc: Detected 2300.001 MHz processor Sep 4 01:15:42.773444 kernel: e820: update [mem 0x00000000-0x00000fff] usable ==> reserved Sep 4 01:15:42.773453 kernel: e820: remove [mem 0x000a0000-0x000fffff] usable Sep 4 01:15:42.773461 kernel: last_pfn = 0x2c0000 max_arch_pfn = 0x10000000000 Sep 4 01:15:42.773471 kernel: MTRR map: 4 entries (2 fixed + 2 variable; max 18), built from 8 variable MTRRs Sep 4 01:15:42.773495 kernel: x86/PAT: Configuration [0-7]: WB WC UC- UC WB WP UC- WT Sep 4 01:15:42.773503 kernel: e820: update [mem 0x48000000-0xffffffff] usable ==> reserved Sep 4 01:15:42.773511 kernel: last_pfn = 0x40000 max_arch_pfn = 0x10000000000 Sep 4 01:15:42.773525 kernel: Using GB pages for direct mapping Sep 4 01:15:42.773534 kernel: ACPI: Early table checksum verification disabled Sep 4 01:15:42.773546 kernel: ACPI: RSDP 0x000000003FFFA014 000024 (v02 VRTUAL) Sep 4 01:15:42.773603 kernel: ACPI: XSDT 0x000000003FFF90E8 00005C (v01 VRTUAL MICROSFT 00000001 MSFT 00000001) Sep 4 01:15:42.773620 kernel: ACPI: FACP 0x000000003FFF8000 000114 (v06 VRTUAL MICROSFT 00000001 MSFT 00000001) Sep 4 01:15:42.773630 kernel: ACPI: DSDT 0x000000003FFD6000 01E22B (v02 MSFTVM DSDT01 00000001 INTL 20230628) Sep 4 01:15:42.773638 kernel: ACPI: FACS 0x000000003FFFE000 000040 Sep 4 01:15:42.773646 kernel: ACPI: OEM0 0x000000003FFF7000 000064 (v01 VRTUAL MICROSFT 00000001 MSFT 00000001) Sep 4 01:15:42.773656 kernel: ACPI: SPCR 0x000000003FFF6000 000050 (v02 VRTUAL MICROSFT 00000001 MSFT 00000001) Sep 4 01:15:42.773664 kernel: ACPI: WAET 0x000000003FFF5000 000028 (v01 VRTUAL MICROSFT 00000001 MSFT 00000001) Sep 4 01:15:42.773672 kernel: ACPI: APIC 0x000000003FFD5000 000058 (v05 HVLITE HVLITETB 00000000 MSHV 00000000) Sep 4 01:15:42.773681 kernel: ACPI: SRAT 0x000000003FFD4000 0000A0 (v03 HVLITE HVLITETB 00000000 MSHV 00000000) Sep 4 01:15:42.773689 kernel: ACPI: BGRT 0x000000003FFD3000 000038 (v01 VRTUAL MICROSFT 00000001 MSFT 00000001) Sep 4 01:15:42.773697 kernel: ACPI: Reserving FACP table memory at [mem 0x3fff8000-0x3fff8113] Sep 4 01:15:42.773707 kernel: ACPI: Reserving DSDT table memory at [mem 0x3ffd6000-0x3fff422a] Sep 4 01:15:42.773715 kernel: ACPI: Reserving FACS table memory at [mem 0x3fffe000-0x3fffe03f] Sep 4 01:15:42.773723 kernel: ACPI: Reserving OEM0 table memory at [mem 0x3fff7000-0x3fff7063] Sep 4 01:15:42.773731 kernel: ACPI: Reserving SPCR table memory at [mem 0x3fff6000-0x3fff604f] Sep 4 01:15:42.773739 kernel: ACPI: Reserving WAET table memory at [mem 0x3fff5000-0x3fff5027] Sep 4 01:15:42.773747 kernel: ACPI: Reserving APIC table memory at [mem 0x3ffd5000-0x3ffd5057] Sep 4 01:15:42.773755 kernel: ACPI: Reserving SRAT table memory at [mem 0x3ffd4000-0x3ffd409f] Sep 4 01:15:42.773764 kernel: ACPI: Reserving BGRT table memory at [mem 0x3ffd3000-0x3ffd3037] Sep 4 01:15:42.773772 kernel: ACPI: SRAT: Node 0 PXM 0 [mem 0x00000000-0x3fffffff] Sep 4 01:15:42.773781 kernel: ACPI: SRAT: Node 0 PXM 0 [mem 0x100000000-0x2bfffffff] Sep 4 01:15:42.773789 kernel: NUMA: Node 0 [mem 0x00001000-0x3fffffff] + [mem 0x100000000-0x2bfffffff] -> [mem 0x00001000-0x2bfffffff] Sep 4 01:15:42.773798 kernel: NODE_DATA(0) allocated [mem 0x2bfff8dc0-0x2bfffffff] Sep 4 01:15:42.773806 kernel: Zone ranges: Sep 4 01:15:42.773814 kernel: DMA [mem 0x0000000000001000-0x0000000000ffffff] Sep 4 01:15:42.773823 kernel: DMA32 [mem 0x0000000001000000-0x00000000ffffffff] Sep 4 01:15:42.773831 kernel: Normal [mem 0x0000000100000000-0x00000002bfffffff] Sep 4 01:15:42.773849 kernel: Device empty Sep 4 01:15:42.773858 kernel: Movable zone start for each node Sep 4 01:15:42.773866 kernel: Early memory node ranges Sep 4 01:15:42.773874 kernel: node 0: [mem 0x0000000000001000-0x000000000009ffff] Sep 4 01:15:42.773882 kernel: node 0: [mem 0x0000000000100000-0x00000000044fdfff] Sep 4 01:15:42.773892 kernel: node 0: [mem 0x00000000048fe000-0x000000003ff1efff] Sep 4 01:15:42.773900 kernel: node 0: [mem 0x000000003ffff000-0x000000003fffffff] Sep 4 01:15:42.773908 kernel: node 0: [mem 0x0000000100000000-0x00000002bfffffff] Sep 4 01:15:42.773916 kernel: Initmem setup node 0 [mem 0x0000000000001000-0x00000002bfffffff] Sep 4 01:15:42.773924 kernel: On node 0, zone DMA: 1 pages in unavailable ranges Sep 4 01:15:42.773932 kernel: On node 0, zone DMA: 96 pages in unavailable ranges Sep 4 01:15:42.773940 kernel: On node 0, zone DMA32: 1024 pages in unavailable ranges Sep 4 01:15:42.773950 kernel: On node 0, zone DMA32: 224 pages in unavailable ranges Sep 4 01:15:42.773958 kernel: ACPI: PM-Timer IO Port: 0x408 Sep 4 01:15:42.773966 kernel: ACPI: LAPIC_NMI (acpi_id[0x01] dfl dfl lint[0x1]) Sep 4 01:15:42.773974 kernel: IOAPIC[0]: apic_id 0, version 17, address 0xfec00000, GSI 0-23 Sep 4 01:15:42.773983 kernel: ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level) Sep 4 01:15:42.773991 kernel: ACPI: Using ACPI (MADT) for SMP configuration information Sep 4 01:15:42.773999 kernel: ACPI: SPCR: console: uart,io,0x3f8,115200 Sep 4 01:15:42.774007 kernel: TSC deadline timer available Sep 4 01:15:42.774016 kernel: CPU topo: Max. logical packages: 1 Sep 4 01:15:42.774024 kernel: CPU topo: Max. logical dies: 1 Sep 4 01:15:42.774032 kernel: CPU topo: Max. dies per package: 1 Sep 4 01:15:42.774040 kernel: CPU topo: Max. threads per core: 2 Sep 4 01:15:42.774049 kernel: CPU topo: Num. cores per package: 1 Sep 4 01:15:42.774057 kernel: CPU topo: Num. threads per package: 2 Sep 4 01:15:42.774064 kernel: CPU topo: Allowing 2 present CPUs plus 0 hotplug CPUs Sep 4 01:15:42.774074 kernel: [mem 0x40000000-0xffffffff] available for PCI devices Sep 4 01:15:42.774082 kernel: Booting paravirtualized kernel on Hyper-V Sep 4 01:15:42.774090 kernel: clocksource: refined-jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1910969940391419 ns Sep 4 01:15:42.774099 kernel: setup_percpu: NR_CPUS:512 nr_cpumask_bits:2 nr_cpu_ids:2 nr_node_ids:1 Sep 4 01:15:42.774107 kernel: percpu: Embedded 60 pages/cpu s207512 r8192 d30056 u1048576 Sep 4 01:15:42.774115 kernel: pcpu-alloc: s207512 r8192 d30056 u1048576 alloc=1*2097152 Sep 4 01:15:42.774123 kernel: pcpu-alloc: [0] 0 1 Sep 4 01:15:42.774132 kernel: Hyper-V: PV spinlocks enabled Sep 4 01:15:42.774140 kernel: PV qspinlock hash table entries: 256 (order: 0, 4096 bytes, linear) Sep 4 01:15:42.774150 kernel: Kernel command line: rootflags=rw mount.usrflags=ro BOOT_IMAGE=/flatcar/vmlinuz-a mount.usr=/dev/mapper/usr verity.usr=PARTUUID=7130c94a-213a-4e5a-8e26-6cce9662f132 rootflags=rw mount.usrflags=ro consoleblank=0 root=LABEL=ROOT console=tty1 console=ttyS0,115200n8 earlyprintk=ttyS0,115200 flatcar.first_boot=detected flatcar.oem.id=azure flatcar.autologin verity.usrhash=0655b4a97b09474b54b9e087df655bcd3d8c009e1539ef38d6f8e422c98586a7 Sep 4 01:15:42.774158 kernel: Dentry cache hash table entries: 1048576 (order: 11, 8388608 bytes, linear) Sep 4 01:15:42.774167 kernel: Inode-cache hash table entries: 524288 (order: 10, 4194304 bytes, linear) Sep 4 01:15:42.774175 kernel: Fallback order for Node 0: 0 Sep 4 01:15:42.774184 kernel: Built 1 zonelists, mobility grouping on. Total pages: 2095807 Sep 4 01:15:42.774193 kernel: Policy zone: Normal Sep 4 01:15:42.774201 kernel: mem auto-init: stack:off, heap alloc:off, heap free:off Sep 4 01:15:42.774209 kernel: software IO TLB: area num 2. Sep 4 01:15:42.774217 kernel: SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1 Sep 4 01:15:42.774225 kernel: ftrace: allocating 39642 entries in 156 pages Sep 4 01:15:42.774233 kernel: ftrace: allocated 156 pages with 4 groups Sep 4 01:15:42.774241 kernel: Dynamic Preempt: voluntary Sep 4 01:15:42.774250 kernel: rcu: Preemptible hierarchical RCU implementation. Sep 4 01:15:42.774260 kernel: rcu: RCU event tracing is enabled. Sep 4 01:15:42.774275 kernel: rcu: RCU restricting CPUs from NR_CPUS=512 to nr_cpu_ids=2. Sep 4 01:15:42.774285 kernel: Trampoline variant of Tasks RCU enabled. Sep 4 01:15:42.774293 kernel: Rude variant of Tasks RCU enabled. Sep 4 01:15:42.774302 kernel: Tracing variant of Tasks RCU enabled. Sep 4 01:15:42.774311 kernel: rcu: RCU calculated value of scheduler-enlistment delay is 100 jiffies. Sep 4 01:15:42.774319 kernel: rcu: Adjusting geometry for rcu_fanout_leaf=16, nr_cpu_ids=2 Sep 4 01:15:42.774328 kernel: RCU Tasks: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=2. Sep 4 01:15:42.774338 kernel: RCU Tasks Rude: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=2. Sep 4 01:15:42.774347 kernel: RCU Tasks Trace: Setting shift to 1 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=2. Sep 4 01:15:42.774356 kernel: Using NULL legacy PIC Sep 4 01:15:42.774364 kernel: NR_IRQS: 33024, nr_irqs: 440, preallocated irqs: 0 Sep 4 01:15:42.774375 kernel: rcu: srcu_init: Setting srcu_struct sizes based on contention. Sep 4 01:15:42.774384 kernel: clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1911260446275000 ns Sep 4 01:15:42.774394 kernel: Console: colour dummy device 80x25 Sep 4 01:15:42.774403 kernel: printk: legacy console [tty1] enabled Sep 4 01:15:42.774412 kernel: printk: legacy console [ttyS0] enabled Sep 4 01:15:42.774421 kernel: printk: legacy bootconsole [earlyser0] disabled Sep 4 01:15:42.774430 kernel: ACPI: Core revision 20240827 Sep 4 01:15:42.774440 kernel: Failed to register legacy timer interrupt Sep 4 01:15:42.774449 kernel: APIC: Switch to symmetric I/O mode setup Sep 4 01:15:42.774458 kernel: x2apic enabled Sep 4 01:15:42.774549 kernel: APIC: Switched APIC routing to: physical x2apic Sep 4 01:15:42.774558 kernel: Hyper-V: Host Build 10.0.26102.3668-3-0 Sep 4 01:15:42.774567 kernel: Hyper-V: enabling crash_kexec_post_notifiers Sep 4 01:15:42.774576 kernel: Hyper-V: Disabling IBT because of Hyper-V bug Sep 4 01:15:42.774587 kernel: Hyper-V: Using IPI hypercalls Sep 4 01:15:42.774596 kernel: APIC: send_IPI() replaced with hv_send_ipi() Sep 4 01:15:42.774604 kernel: APIC: send_IPI_mask() replaced with hv_send_ipi_mask() Sep 4 01:15:42.774613 kernel: APIC: send_IPI_mask_allbutself() replaced with hv_send_ipi_mask_allbutself() Sep 4 01:15:42.774623 kernel: APIC: send_IPI_allbutself() replaced with hv_send_ipi_allbutself() Sep 4 01:15:42.774632 kernel: APIC: send_IPI_all() replaced with hv_send_ipi_all() Sep 4 01:15:42.774641 kernel: APIC: send_IPI_self() replaced with hv_send_ipi_self() Sep 4 01:15:42.774651 kernel: clocksource: tsc-early: mask: 0xffffffffffffffff max_cycles: 0x212735f0517, max_idle_ns: 440795237604 ns Sep 4 01:15:42.774659 kernel: Calibrating delay loop (skipped), value calculated using timer frequency.. 4600.00 BogoMIPS (lpj=2300001) Sep 4 01:15:42.774668 kernel: x86/cpu: User Mode Instruction Prevention (UMIP) activated Sep 4 01:15:42.774676 kernel: Last level iTLB entries: 4KB 0, 2MB 0, 4MB 0 Sep 4 01:15:42.774684 kernel: Last level dTLB entries: 4KB 0, 2MB 0, 4MB 0, 1GB 0 Sep 4 01:15:42.774692 kernel: Spectre V1 : Mitigation: usercopy/swapgs barriers and __user pointer sanitization Sep 4 01:15:42.774700 kernel: Spectre V2 : Mitigation: Retpolines Sep 4 01:15:42.774708 kernel: Spectre V2 : Spectre v2 / SpectreRSB: Filling RSB on context switch and VMEXIT Sep 4 01:15:42.774719 kernel: RETBleed: WARNING: Spectre v2 mitigation leaves CPU vulnerable to RETBleed attacks, data leaks possible! Sep 4 01:15:42.774727 kernel: RETBleed: Vulnerable Sep 4 01:15:42.774736 kernel: Speculative Store Bypass: Vulnerable Sep 4 01:15:42.774744 kernel: active return thunk: its_return_thunk Sep 4 01:15:42.774753 kernel: ITS: Mitigation: Aligned branch/return thunks Sep 4 01:15:42.774761 kernel: x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers' Sep 4 01:15:42.774769 kernel: x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' Sep 4 01:15:42.774777 kernel: x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers' Sep 4 01:15:42.774785 kernel: x86/fpu: Supporting XSAVE feature 0x020: 'AVX-512 opmask' Sep 4 01:15:42.774793 kernel: x86/fpu: Supporting XSAVE feature 0x040: 'AVX-512 Hi256' Sep 4 01:15:42.774803 kernel: x86/fpu: Supporting XSAVE feature 0x080: 'AVX-512 ZMM_Hi256' Sep 4 01:15:42.774811 kernel: x86/fpu: Supporting XSAVE feature 0x800: 'Control-flow User registers' Sep 4 01:15:42.774819 kernel: x86/fpu: Supporting XSAVE feature 0x20000: 'AMX Tile config' Sep 4 01:15:42.774827 kernel: x86/fpu: Supporting XSAVE feature 0x40000: 'AMX Tile data' Sep 4 01:15:42.774836 kernel: x86/fpu: xstate_offset[2]: 576, xstate_sizes[2]: 256 Sep 4 01:15:42.774882 kernel: x86/fpu: xstate_offset[5]: 832, xstate_sizes[5]: 64 Sep 4 01:15:42.774891 kernel: x86/fpu: xstate_offset[6]: 896, xstate_sizes[6]: 512 Sep 4 01:15:42.774899 kernel: x86/fpu: xstate_offset[7]: 1408, xstate_sizes[7]: 1024 Sep 4 01:15:42.774907 kernel: x86/fpu: xstate_offset[11]: 2432, xstate_sizes[11]: 16 Sep 4 01:15:42.774916 kernel: x86/fpu: xstate_offset[17]: 2496, xstate_sizes[17]: 64 Sep 4 01:15:42.774925 kernel: x86/fpu: xstate_offset[18]: 2560, xstate_sizes[18]: 8192 Sep 4 01:15:42.774936 kernel: x86/fpu: Enabled xstate features 0x608e7, context size is 10752 bytes, using 'compacted' format. Sep 4 01:15:42.774944 kernel: Freeing SMP alternatives memory: 32K Sep 4 01:15:42.774953 kernel: pid_max: default: 32768 minimum: 301 Sep 4 01:15:42.774961 kernel: LSM: initializing lsm=lockdown,capability,landlock,selinux,ima Sep 4 01:15:42.774969 kernel: landlock: Up and running. Sep 4 01:15:42.774977 kernel: SELinux: Initializing. Sep 4 01:15:42.774985 kernel: Mount-cache hash table entries: 16384 (order: 5, 131072 bytes, linear) Sep 4 01:15:42.774992 kernel: Mountpoint-cache hash table entries: 16384 (order: 5, 131072 bytes, linear) Sep 4 01:15:42.775000 kernel: smpboot: CPU0: Intel INTEL(R) XEON(R) PLATINUM 8573C (family: 0x6, model: 0xcf, stepping: 0x2) Sep 4 01:15:42.775009 kernel: Performance Events: unsupported p6 CPU model 207 no PMU driver, software events only. Sep 4 01:15:42.775020 kernel: signal: max sigframe size: 11952 Sep 4 01:15:42.775029 kernel: rcu: Hierarchical SRCU implementation. Sep 4 01:15:42.775038 kernel: rcu: Max phase no-delay instances is 400. Sep 4 01:15:42.775047 kernel: Timer migration: 1 hierarchy levels; 8 children per group; 1 crossnode level Sep 4 01:15:42.775056 kernel: NMI watchdog: Perf NMI watchdog permanently disabled Sep 4 01:15:42.775066 kernel: smp: Bringing up secondary CPUs ... Sep 4 01:15:42.775075 kernel: smpboot: x86: Booting SMP configuration: Sep 4 01:15:42.775086 kernel: .... node #0, CPUs: #1 Sep 4 01:15:42.775094 kernel: smp: Brought up 1 node, 2 CPUs Sep 4 01:15:42.775103 kernel: smpboot: Total of 2 processors activated (9200.00 BogoMIPS) Sep 4 01:15:42.775112 kernel: Memory: 8059804K/8383228K available (14336K kernel code, 2453K rwdata, 31668K rodata, 15576K init, 2440K bss, 317204K reserved, 0K cma-reserved) Sep 4 01:15:42.775122 kernel: devtmpfs: initialized Sep 4 01:15:42.775131 kernel: x86/mm: Memory block size: 128MB Sep 4 01:15:42.775139 kernel: ACPI: PM: Registering ACPI NVS region [mem 0x3fffb000-0x3fffefff] (16384 bytes) Sep 4 01:15:42.775148 kernel: futex hash table entries: 512 (order: 3, 32768 bytes, linear) Sep 4 01:15:42.775158 kernel: pinctrl core: initialized pinctrl subsystem Sep 4 01:15:42.775167 kernel: NET: Registered PF_NETLINK/PF_ROUTE protocol family Sep 4 01:15:42.775176 kernel: audit: initializing netlink subsys (disabled) Sep 4 01:15:42.775185 kernel: audit: type=2000 audit(1788484537.083:1): state=initialized audit_enabled=0 res=1 Sep 4 01:15:42.775194 kernel: thermal_sys: Registered thermal governor 'step_wise' Sep 4 01:15:42.775203 kernel: thermal_sys: Registered thermal governor 'user_space' Sep 4 01:15:42.775212 kernel: cpuidle: using governor menu Sep 4 01:15:42.775222 kernel: efi: Freeing EFI boot services memory: 33596K Sep 4 01:15:42.775231 kernel: acpiphp: ACPI Hot Plug PCI Controller Driver version: 0.5 Sep 4 01:15:42.775240 kernel: dca service started, version 1.12.1 Sep 4 01:15:42.775249 kernel: e820: reserve RAM buffer [mem 0x044fe000-0x07ffffff] Sep 4 01:15:42.775257 kernel: e820: reserve RAM buffer [mem 0x3ff1f000-0x3fffffff] Sep 4 01:15:42.775266 kernel: kprobes: kprobe jump-optimization is enabled. All kprobes are optimized if possible. Sep 4 01:15:42.775275 kernel: HugeTLB: registered 1.00 GiB page size, pre-allocated 0 pages Sep 4 01:15:42.775285 kernel: HugeTLB: 16380 KiB vmemmap can be freed for a 1.00 GiB page Sep 4 01:15:42.775293 kernel: HugeTLB: registered 2.00 MiB page size, pre-allocated 0 pages Sep 4 01:15:42.775300 kernel: HugeTLB: 28 KiB vmemmap can be freed for a 2.00 MiB page Sep 4 01:15:42.775308 kernel: ACPI: Added _OSI(Module Device) Sep 4 01:15:42.775317 kernel: ACPI: Added _OSI(Processor Device) Sep 4 01:15:42.775326 kernel: ACPI: Added _OSI(Processor Aggregator Device) Sep 4 01:15:42.775334 kernel: ACPI: 1 ACPI AML tables successfully acquired and loaded Sep 4 01:15:42.775344 kernel: ACPI: Interpreter enabled Sep 4 01:15:42.775353 kernel: ACPI: PM: (supports S0 S5) Sep 4 01:15:42.775361 kernel: ACPI: Using IOAPIC for interrupt routing Sep 4 01:15:42.775370 kernel: PCI: Using host bridge windows from ACPI; if necessary, use "pci=nocrs" and report a bug Sep 4 01:15:42.775379 kernel: PCI: Ignoring E820 reservations for host bridge windows Sep 4 01:15:42.775388 kernel: ACPI: Enabled 1 GPEs in block 00 to 0F Sep 4 01:15:42.775396 kernel: iommu: Default domain type: Translated Sep 4 01:15:42.775407 kernel: iommu: DMA domain TLB invalidation policy: lazy mode Sep 4 01:15:42.775415 kernel: efivars: Registered efivars operations Sep 4 01:15:42.775424 kernel: PCI: Using ACPI for IRQ routing Sep 4 01:15:42.775433 kernel: PCI: System does not support PCI Sep 4 01:15:42.775441 kernel: vgaarb: loaded Sep 4 01:15:42.775450 kernel: clocksource: Switched to clocksource tsc-early Sep 4 01:15:42.775459 kernel: VFS: Disk quotas dquot_6.6.0 Sep 4 01:15:42.775469 kernel: VFS: Dquot-cache hash table entries: 512 (order 0, 4096 bytes) Sep 4 01:15:42.775478 kernel: pnp: PnP ACPI init Sep 4 01:15:42.775485 kernel: pnp: PnP ACPI: found 3 devices Sep 4 01:15:42.775494 kernel: clocksource: acpi_pm: mask: 0xffffff max_cycles: 0xffffff, max_idle_ns: 2085701024 ns Sep 4 01:15:42.775503 kernel: NET: Registered PF_INET protocol family Sep 4 01:15:42.775511 kernel: IP idents hash table entries: 131072 (order: 8, 1048576 bytes, linear) Sep 4 01:15:42.775520 kernel: tcp_listen_portaddr_hash hash table entries: 4096 (order: 4, 65536 bytes, linear) Sep 4 01:15:42.775531 kernel: Table-perturb hash table entries: 65536 (order: 6, 262144 bytes, linear) Sep 4 01:15:42.775540 kernel: TCP established hash table entries: 65536 (order: 7, 524288 bytes, linear) Sep 4 01:15:42.775548 kernel: TCP bind hash table entries: 65536 (order: 9, 2097152 bytes, linear) Sep 4 01:15:42.775557 kernel: TCP: Hash tables configured (established 65536 bind 65536) Sep 4 01:15:42.775566 kernel: UDP hash table entries: 4096 (order: 5, 131072 bytes, linear) Sep 4 01:15:42.775574 kernel: UDP-Lite hash table entries: 4096 (order: 5, 131072 bytes, linear) Sep 4 01:15:42.775583 kernel: NET: Registered PF_UNIX/PF_LOCAL protocol family Sep 4 01:15:42.775593 kernel: NET: Registered PF_XDP protocol family Sep 4 01:15:42.775602 kernel: PCI: CLS 0 bytes, default 64 Sep 4 01:15:42.775611 kernel: PCI-DMA: Using software bounce buffering for IO (SWIOTLB) Sep 4 01:15:42.775620 kernel: software IO TLB: mapped [mem 0x000000003a984000-0x000000003e984000] (64MB) Sep 4 01:15:42.775629 kernel: RAPL PMU: API unit is 2^-32 Joules, 1 fixed counters, 10737418240 ms ovfl timer Sep 4 01:15:42.775637 kernel: RAPL PMU: hw unit of domain psys 2^-0 Joules Sep 4 01:15:42.775645 kernel: clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x212735f0517, max_idle_ns: 440795237604 ns Sep 4 01:15:42.775655 kernel: clocksource: Switched to clocksource tsc Sep 4 01:15:42.775664 kernel: Initialise system trusted keyrings Sep 4 01:15:42.775672 kernel: workingset: timestamp_bits=39 max_order=21 bucket_order=0 Sep 4 01:15:42.775680 kernel: Key type asymmetric registered Sep 4 01:15:42.775689 kernel: Asymmetric key parser 'x509' registered Sep 4 01:15:42.775697 kernel: Block layer SCSI generic (bsg) driver version 0.4 loaded (major 250) Sep 4 01:15:42.775706 kernel: io scheduler mq-deadline registered Sep 4 01:15:42.775716 kernel: io scheduler kyber registered Sep 4 01:15:42.775725 kernel: io scheduler bfq registered Sep 4 01:15:42.775734 kernel: ioatdma: Intel(R) QuickData Technology Driver 5.00 Sep 4 01:15:42.775743 kernel: Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled Sep 4 01:15:42.775752 kernel: 00:00: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A Sep 4 01:15:42.775761 kernel: 00:01: ttyS1 at I/O 0x2f8 (irq = 3, base_baud = 115200) is a 16550A Sep 4 01:15:42.775769 kernel: serial8250: ttyS2 at I/O 0x3e8 (irq = 4, base_baud = 115200) is a 16550A Sep 4 01:15:42.775780 kernel: i8042: PNP: No PS/2 controller found. Sep 4 01:15:42.775959 kernel: rtc_cmos 00:02: registered as rtc0 Sep 4 01:15:42.776055 kernel: rtc_cmos 00:02: setting system clock to 2026-09-04T01:15:39 UTC (1788484539) Sep 4 01:15:42.776142 kernel: rtc_cmos 00:02: alarms up to one month, 114 bytes nvram Sep 4 01:15:42.776152 kernel: intel_pstate: Intel P-state driver initializing Sep 4 01:15:42.776161 kernel: efifb: probing for efifb Sep 4 01:15:42.776171 kernel: efifb: framebuffer at 0x40000000, using 3072k, total 3072k Sep 4 01:15:42.776180 kernel: efifb: mode is 1024x768x32, linelength=4096, pages=1 Sep 4 01:15:42.776189 kernel: efifb: scrolling: redraw Sep 4 01:15:42.776197 kernel: efifb: Truecolor: size=8:8:8:8, shift=24:16:8:0 Sep 4 01:15:42.776206 kernel: Console: switching to colour frame buffer device 128x48 Sep 4 01:15:42.776214 kernel: fb0: EFI VGA frame buffer device Sep 4 01:15:42.776222 kernel: pstore: Using crash dump compression: deflate Sep 4 01:15:42.776231 kernel: pstore: Registered efi_pstore as persistent store backend Sep 4 01:15:42.776242 kernel: NET: Registered PF_INET6 protocol family Sep 4 01:15:42.776251 kernel: Segment Routing with IPv6 Sep 4 01:15:42.776259 kernel: In-situ OAM (IOAM) with IPv6 Sep 4 01:15:42.776268 kernel: NET: Registered PF_PACKET protocol family Sep 4 01:15:42.776276 kernel: Key type dns_resolver registered Sep 4 01:15:42.776285 kernel: IPI shorthand broadcast: enabled Sep 4 01:15:42.776293 kernel: sched_clock: Marking stable (1874135574, 93527471)->(2263824672, -296161627) Sep 4 01:15:42.776303 kernel: registered taskstats version 1 Sep 4 01:15:42.776311 kernel: Loading compiled-in X.509 certificates Sep 4 01:15:42.776319 kernel: Loaded X.509 cert 'Kinvolk GmbH: Module signing key for 6.12.108-flatcar: e4f661276e94b86586896fd49c53a21a98ce7d25' Sep 4 01:15:42.776326 kernel: Demotion targets for Node 0: null Sep 4 01:15:42.776335 kernel: Key type .fscrypt registered Sep 4 01:15:42.776344 kernel: Key type fscrypt-provisioning registered Sep 4 01:15:42.776352 kernel: ima: No TPM chip found, activating TPM-bypass! Sep 4 01:15:42.776362 kernel: ima: Allocated hash algorithm: sha1 Sep 4 01:15:42.776370 kernel: ima: No architecture policies found Sep 4 01:15:42.776378 kernel: clk: Disabling unused clocks Sep 4 01:15:42.776387 kernel: Freeing unused kernel image (initmem) memory: 15576K Sep 4 01:15:42.776395 kernel: Write protecting the kernel read-only data: 47104k Sep 4 01:15:42.776404 kernel: Freeing unused kernel image (rodata/data gap) memory: 1100K Sep 4 01:15:42.776413 kernel: Run /init as init process Sep 4 01:15:42.776423 kernel: with arguments: Sep 4 01:15:42.776432 kernel: /init Sep 4 01:15:42.776440 kernel: with environment: Sep 4 01:15:42.776449 kernel: HOME=/ Sep 4 01:15:42.776457 kernel: TERM=linux Sep 4 01:15:42.776466 kernel: hv_vmbus: hv_mmio=[mem 0x40000000-0xfed3ffff],[mem 0xfc0000000-0xfffffffff] fb=[mem 0x40000000-0x47ffffff] Sep 4 01:15:42.776475 kernel: hv_vmbus: Vmbus version:5.3 Sep 4 01:15:42.776483 kernel: pps_core: LinuxPPS API ver. 1 registered Sep 4 01:15:42.776494 kernel: pps_core: Software ver. 5.3.6 - Copyright 2005-2007 Rodolfo Giometti Sep 4 01:15:42.776503 kernel: PTP clock support registered Sep 4 01:15:42.776512 kernel: hv_utils: Registering HyperV Utility Driver Sep 4 01:15:42.776520 kernel: hv_vmbus: registering driver hv_utils Sep 4 01:15:42.776530 kernel: hv_utils: Shutdown IC version 3.2 Sep 4 01:15:42.776539 kernel: hv_utils: Heartbeat IC version 3.0 Sep 4 01:15:42.776547 kernel: hv_utils: TimeSync IC version 4.0 Sep 4 01:15:42.776557 kernel: SCSI subsystem initialized Sep 4 01:15:42.776566 kernel: hv_vmbus: registering driver hv_pci Sep 4 01:15:42.776692 kernel: hv_pci 7ad35d50-c05b-47ab-b3a0-56a9a845852b: PCI VMBus probing: Using version 0x10004 Sep 4 01:15:42.776786 kernel: hv_pci 7ad35d50-c05b-47ab-b3a0-56a9a845852b: PCI host bridge to bus c05b:00 Sep 4 01:15:42.776915 kernel: pci_bus c05b:00: root bus resource [mem 0xfc0000000-0xfc007ffff window] Sep 4 01:15:42.777015 kernel: pci_bus c05b:00: No busn resource found for root bus, will use [bus 00-ff] Sep 4 01:15:42.777164 kernel: pci c05b:00:00.0: [1414:00a9] type 00 class 0x010802 PCIe Endpoint Sep 4 01:15:42.777281 kernel: pci c05b:00:00.0: BAR 0 [mem 0xfc0000000-0xfc007ffff 64bit] Sep 4 01:15:42.777396 kernel: pci_bus c05b:00: busn_res: [bus 00-ff] end is updated to 00 Sep 4 01:15:42.777518 kernel: pci c05b:00:00.0: BAR 0 [mem 0xfc0000000-0xfc007ffff 64bit]: assigned Sep 4 01:15:42.777532 kernel: hv_vmbus: registering driver hv_storvsc Sep 4 01:15:42.777662 kernel: scsi host0: storvsc_host_t Sep 4 01:15:42.777797 kernel: scsi 0:0:0:2: CD-ROM Msft Virtual DVD-ROM 1.0 PQ: 0 ANSI: 5 Sep 4 01:15:42.777810 kernel: hid: raw HID events driver (C) Jiri Kosina Sep 4 01:15:42.777820 kernel: hv_vmbus: registering driver hid_hyperv Sep 4 01:15:42.777830 kernel: input: Microsoft Vmbus HID-compliant Mouse as /devices/0006:045E:0621.0001/input/input0 Sep 4 01:15:42.777964 kernel: hid-hyperv 0006:045E:0621.0001: input: VIRTUAL HID v0.01 Mouse [Microsoft Vmbus HID-compliant Mouse] on Sep 4 01:15:42.777978 kernel: hv_vmbus: registering driver hyperv_keyboard Sep 4 01:15:42.777989 kernel: input: AT Translated Set 2 keyboard as /devices/LNXSYSTM:00/LNXSYBUS:00/ACPI0004:00/MSFT1000:00/d34b2567-b9b6-42b9-8778-0a4ec0b955bf/serio0/input/input1 Sep 4 01:15:42.778117 kernel: nvme nvme0: pci function c05b:00:00.0 Sep 4 01:15:42.778270 kernel: nvme c05b:00:00.0: enabling device (0000 -> 0002) Sep 4 01:15:42.778379 kernel: nvme nvme0: 2/0/0 default/read/poll queues Sep 4 01:15:42.778396 kernel: nvme0n1: p1 p2 p3 p4 p6 p7 p9 Sep 4 01:15:42.778533 kernel: sr 0:0:0:2: [sr0] scsi-1 drive Sep 4 01:15:42.778543 kernel: cdrom: Uniform CD-ROM driver Revision: 3.20 Sep 4 01:15:42.778649 kernel: sr 0:0:0:2: Attached scsi CD-ROM sr0 Sep 4 01:15:42.778660 kernel: device-mapper: core: CONFIG_IMA_DISABLE_HTABLE is disabled. Duplicate IMA measurements will not be recorded in the IMA log. Sep 4 01:15:42.778669 kernel: device-mapper: uevent: version 1.0.3 Sep 4 01:15:42.778692 kernel: device-mapper: ioctl: 4.48.0-ioctl (2023-03-01) initialised: dm-devel@lists.linux.dev Sep 4 01:15:42.778703 kernel: device-mapper: verity: sha256 using shash "sha256-generic" Sep 4 01:15:42.778713 kernel: raid6: avx512x4 gen() 46384 MB/s Sep 4 01:15:42.778722 kernel: raid6: avx512x2 gen() 46174 MB/s Sep 4 01:15:42.778731 kernel: raid6: avx512x1 gen() 28126 MB/s Sep 4 01:15:42.778740 kernel: raid6: avx2x4 gen() 40697 MB/s Sep 4 01:15:42.778750 kernel: raid6: avx2x2 gen() 42457 MB/s Sep 4 01:15:42.778761 kernel: raid6: avx2x1 gen() 31851 MB/s Sep 4 01:15:42.778771 kernel: raid6: using algorithm avx512x4 gen() 46384 MB/s Sep 4 01:15:42.778780 kernel: raid6: .... xor() 7573 MB/s, rmw enabled Sep 4 01:15:42.778788 kernel: raid6: using avx512x2 recovery algorithm Sep 4 01:15:42.778796 kernel: xor: automatically using best checksumming function avx Sep 4 01:15:42.778806 kernel: Btrfs loaded, zoned=no, fsverity=no Sep 4 01:15:42.778815 kernel: BTRFS: device fsid ec4992cc-7ac8-46f8-84e6-63f571b32c56 devid 1 transid 38 /dev/mapper/usr (254:0) scanned by mount (964) Sep 4 01:15:42.778827 kernel: BTRFS info (device dm-0): first mount of filesystem ec4992cc-7ac8-46f8-84e6-63f571b32c56 Sep 4 01:15:42.778837 kernel: BTRFS info (device dm-0): using crc32c (crc32c-intel) checksum algorithm Sep 4 01:15:42.778860 kernel: BTRFS info (device dm-0 state E): enabling ssd optimizations Sep 4 01:15:42.778870 kernel: BTRFS info (device dm-0 state E): disabling log replay at mount time Sep 4 01:15:42.778879 kernel: BTRFS info (device dm-0 state E): enabling free space tree Sep 4 01:15:42.778888 kernel: loop: module loaded Sep 4 01:15:42.778898 kernel: loop0: detected capacity change from 0 to 100576 Sep 4 01:15:42.778908 kernel: squashfs: version 4.0 (2009/01/31) Phillip Lougher Sep 4 01:15:42.778920 systemd[1]: Successfully made /usr/ read-only. Sep 4 01:15:42.778933 systemd[1]: systemd 257.9 running in system mode (+PAM +AUDIT +SELINUX -APPARMOR +IMA +IPE +SMACK +SECCOMP -GCRYPT -GNUTLS +OPENSSL -ACL +BLKID +CURL +ELFUTILS -FIDO2 +IDN2 -IDN +IPTC +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 -PWQUALITY -P11KIT -QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD -BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP -SYSVINIT +LIBARCHIVE) Sep 4 01:15:42.778944 systemd[1]: Detected virtualization microsoft. Sep 4 01:15:42.778953 systemd[1]: Detected architecture x86-64. Sep 4 01:15:42.778963 systemd[1]: Running in initrd. Sep 4 01:15:42.778975 systemd[1]: No hostname configured, using default hostname. Sep 4 01:15:42.778985 systemd[1]: Hostname set to . Sep 4 01:15:42.778997 systemd[1]: Initializing machine ID from random generator. Sep 4 01:15:42.779007 systemd[1]: Queued start job for default target initrd.target. Sep 4 01:15:42.779015 systemd[1]: Unnecessary job was removed for dev-mapper-usr.device - /dev/mapper/usr. Sep 4 01:15:42.779025 systemd[1]: Started clevis-luks-askpass.path - Forward Password Requests to Clevis Directory Watch. Sep 4 01:15:42.779036 systemd[1]: Started systemd-ask-password-console.path - Dispatch Password Requests to Console Directory Watch. Sep 4 01:15:42.779046 systemd[1]: Expecting device dev-disk-by\x2dlabel-EFI\x2dSYSTEM.device - /dev/disk/by-label/EFI-SYSTEM... Sep 4 01:15:42.779055 systemd[1]: Expecting device dev-disk-by\x2dlabel-OEM.device - /dev/disk/by-label/OEM... Sep 4 01:15:42.779064 systemd[1]: Expecting device dev-disk-by\x2dlabel-ROOT.device - /dev/disk/by-label/ROOT... Sep 4 01:15:42.779075 systemd[1]: Expecting device dev-disk-by\x2dpartlabel-USR\x2dA.device - /dev/disk/by-partlabel/USR-A... Sep 4 01:15:42.779085 systemd[1]: Reached target cryptsetup-pre.target - Local Encrypted Volumes (Pre). Sep 4 01:15:42.779096 systemd[1]: Reached target cryptsetup.target - Local Encrypted Volumes. Sep 4 01:15:42.779106 systemd[1]: Reached target initrd-usr-fs.target - Initrd /usr File System. Sep 4 01:15:42.779117 systemd[1]: Reached target paths.target - Path Units. Sep 4 01:15:42.779127 systemd[1]: Reached target slices.target - Slice Units. Sep 4 01:15:42.779139 systemd[1]: Reached target swap.target - Swaps. Sep 4 01:15:42.779149 systemd[1]: Reached target timers.target - Timer Units. Sep 4 01:15:42.779159 systemd[1]: Listening on iscsid.socket - Open-iSCSI iscsid Socket. Sep 4 01:15:42.779169 systemd[1]: Listening on iscsiuio.socket - Open-iSCSI iscsiuio Socket. Sep 4 01:15:42.779180 systemd[1]: Listening on systemd-journald-audit.socket - Journal Audit Socket. Sep 4 01:15:42.779190 systemd[1]: Listening on systemd-journald-dev-log.socket - Journal Socket (/dev/log). Sep 4 01:15:42.779200 systemd[1]: Listening on systemd-journald.socket - Journal Sockets. Sep 4 01:15:42.779213 systemd[1]: Listening on systemd-networkd.socket - Network Service Netlink Socket. Sep 4 01:15:42.779223 systemd[1]: Listening on systemd-udevd-control.socket - udev Control Socket. Sep 4 01:15:42.779233 systemd[1]: Listening on systemd-udevd-kernel.socket - udev Kernel Socket. Sep 4 01:15:42.779243 systemd[1]: Reached target sockets.target - Socket Units. Sep 4 01:15:42.779254 systemd[1]: afterburn-network-kargs.service - Afterburn Initrd Setup Network Kernel Arguments was skipped because no trigger condition checks were met. Sep 4 01:15:42.779265 systemd[1]: Starting ignition-setup-pre.service - Ignition env setup... Sep 4 01:15:42.779275 systemd[1]: Starting kmod-static-nodes.service - Create List of Static Device Nodes... Sep 4 01:15:42.779287 systemd[1]: Finished network-cleanup.service - Network Cleanup. Sep 4 01:15:42.779297 systemd[1]: systemd-battery-check.service - Check battery level during early boot was skipped because of an unmet condition check (ConditionDirectoryNotEmpty=/sys/class/power_supply). Sep 4 01:15:42.779307 systemd[1]: Starting systemd-fsck-usr.service... Sep 4 01:15:42.779318 systemd[1]: Starting systemd-journald.service - Journal Service... Sep 4 01:15:42.779328 systemd[1]: Starting systemd-modules-load.service - Load Kernel Modules... Sep 4 01:15:42.779340 systemd[1]: Starting systemd-vconsole-setup.service - Virtual Console Setup... Sep 4 01:15:42.779350 systemd[1]: Finished ignition-setup-pre.service - Ignition env setup. Sep 4 01:15:42.779361 systemd[1]: Finished kmod-static-nodes.service - Create List of Static Device Nodes. Sep 4 01:15:42.779371 systemd[1]: Finished systemd-fsck-usr.service. Sep 4 01:15:42.779382 systemd[1]: Starting systemd-tmpfiles-setup-dev-early.service - Create Static Device Nodes in /dev gracefully... Sep 4 01:15:42.779394 kernel: bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this. Sep 4 01:15:42.779421 systemd-journald[1097]: Collecting audit messages is enabled. Sep 4 01:15:42.779444 kernel: Bridge firewalling registered Sep 4 01:15:42.779455 systemd-journald[1097]: Journal started Sep 4 01:15:42.779475 systemd-journald[1097]: Runtime Journal (/run/log/journal/bae34cf12cc54ab5af05bc01f0978f77) is 8M, max 158.5M, 150.5M free. Sep 4 01:15:42.781010 systemd[1]: Started systemd-journald.service - Journal Service. Sep 4 01:15:42.781872 systemd[1]: Finished systemd-tmpfiles-setup-dev-early.service - Create Static Device Nodes in /dev gracefully. Sep 4 01:15:42.785963 systemd[1]: Starting systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev... Sep 4 01:15:42.786771 systemd[1]: Starting systemd-tmpfiles-setup.service - Create System Files and Directories... Sep 4 01:15:42.780000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-journald comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.793911 systemd-modules-load[1101]: Inserted module 'br_netfilter' Sep 4 01:15:42.799271 kernel: audit: type=1130 audit(1788484542.780:2): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-journald comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.800713 kernel: audit: type=1130 audit(1788484542.780:3): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev-early comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.780000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev-early comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.801036 systemd[1]: Finished systemd-modules-load.service - Load Kernel Modules. Sep 4 01:15:42.803000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-modules-load comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.807859 kernel: audit: type=1130 audit(1788484542.803:4): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-modules-load comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.808132 systemd[1]: Finished systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev. Sep 4 01:15:42.808000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.814417 kernel: audit: type=1130 audit(1788484542.808:5): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.816264 systemd[1]: Starting systemd-sysctl.service - Apply Kernel Variables... Sep 4 01:15:42.818120 systemd-tmpfiles[1114]: /usr/lib/tmpfiles.d/var.conf:14: Duplicate line for path "/var/log", ignoring. Sep 4 01:15:42.838578 systemd[1]: Finished systemd-tmpfiles-setup.service - Create System Files and Directories. Sep 4 01:15:42.843241 kernel: audit: type=1130 audit(1788484542.837:6): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.837000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.866701 systemd[1]: Finished systemd-sysctl.service - Apply Kernel Variables. Sep 4 01:15:42.866000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.873521 kernel: audit: type=1130 audit(1788484542.866:7): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.873689 systemd[1]: Starting systemd-resolved.service - Network Name Resolution... Sep 4 01:15:42.878527 kernel: audit: type=1334 audit(1788484542.866:8): prog-id=6 op=LOAD Sep 4 01:15:42.866000 audit: BPF prog-id=6 op=LOAD Sep 4 01:15:42.884278 systemd[1]: Finished systemd-vconsole-setup.service - Virtual Console Setup. Sep 4 01:15:42.885000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.890866 kernel: audit: type=1130 audit(1788484542.885:9): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.891011 systemd[1]: Starting dracut-cmdline-ask.service - dracut ask for additional cmdline parameters... Sep 4 01:15:42.914322 systemd[1]: Finished dracut-cmdline-ask.service - dracut ask for additional cmdline parameters. Sep 4 01:15:42.918000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline-ask comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.922956 systemd[1]: Starting dracut-cmdline.service - dracut cmdline hook... Sep 4 01:15:42.924078 kernel: audit: type=1130 audit(1788484542.918:10): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline-ask comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.932585 systemd-resolved[1124]: Positive Trust Anchors: Sep 4 01:15:42.932600 systemd-resolved[1124]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d Sep 4 01:15:42.932603 systemd-resolved[1124]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 Sep 4 01:15:42.932636 systemd-resolved[1124]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test Sep 4 01:15:42.957402 systemd-resolved[1124]: Defaulting to hostname 'linux'. Sep 4 01:15:42.959318 systemd[1]: Started systemd-resolved.service - Network Name Resolution. Sep 4 01:15:42.959000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-resolved comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:42.962235 systemd[1]: Reached target nss-lookup.target - Host and Network Name Lookups. Sep 4 01:15:42.968382 dracut-cmdline[1138]: dracut-109 Sep 4 01:15:42.971125 dracut-cmdline[1138]: Using kernel command line parameters: SYSTEMD_SULOGIN_FORCE=1 rootflags=rw mount.usrflags=ro BOOT_IMAGE=/flatcar/vmlinuz-a mount.usr=/dev/mapper/usr verity.usr=PARTUUID=7130c94a-213a-4e5a-8e26-6cce9662f132 rootflags=rw mount.usrflags=ro consoleblank=0 root=LABEL=ROOT console=tty1 console=ttyS0,115200n8 earlyprintk=ttyS0,115200 flatcar.first_boot=detected flatcar.oem.id=azure flatcar.autologin verity.usrhash=0655b4a97b09474b54b9e087df655bcd3d8c009e1539ef38d6f8e422c98586a7 Sep 4 01:15:43.088867 kernel: Loading iSCSI transport class v2.0-870. Sep 4 01:15:43.174865 kernel: iscsi: registered transport (tcp) Sep 4 01:15:43.224997 kernel: iscsi: registered transport (qla4xxx) Sep 4 01:15:43.225062 kernel: QLogic iSCSI HBA Driver Sep 4 01:15:43.274323 systemd[1]: Starting systemd-network-generator.service - Generate network units from Kernel command line... Sep 4 01:15:43.291459 systemd[1]: Finished systemd-network-generator.service - Generate network units from Kernel command line. Sep 4 01:15:43.293000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-network-generator comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.295826 systemd[1]: Reached target network-pre.target - Preparation for Network. Sep 4 01:15:43.330819 systemd[1]: Finished dracut-cmdline.service - dracut cmdline hook. Sep 4 01:15:43.329000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.333721 systemd[1]: Starting dracut-pre-udev.service - dracut pre-udev hook... Sep 4 01:15:43.337151 systemd[1]: Starting parse-ip-for-networkd.service - Write systemd-networkd units from cmdline... Sep 4 01:15:43.367670 systemd[1]: Finished dracut-pre-udev.service - dracut pre-udev hook. Sep 4 01:15:43.368000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-udev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.369000 audit: BPF prog-id=7 op=LOAD Sep 4 01:15:43.369000 audit: BPF prog-id=8 op=LOAD Sep 4 01:15:43.373000 systemd[1]: Starting systemd-udevd.service - Rule-based Manager for Device Events and Files... Sep 4 01:15:43.402834 systemd-udevd[1373]: Using default interface naming scheme 'v257'. Sep 4 01:15:43.414649 systemd[1]: Started systemd-udevd.service - Rule-based Manager for Device Events and Files. Sep 4 01:15:43.427859 kernel: kauditd_printk_skb: 6 callbacks suppressed Sep 4 01:15:43.427900 kernel: audit: type=1130 audit(1788484543.418:17): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udevd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.418000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udevd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.426041 systemd[1]: Starting dracut-pre-trigger.service - dracut pre-trigger hook... Sep 4 01:15:43.435540 systemd[1]: Finished parse-ip-for-networkd.service - Write systemd-networkd units from cmdline. Sep 4 01:15:43.442000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=parse-ip-for-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.447641 dracut-pre-trigger[1462]: rd.md=0: removing MD RAID activation Sep 4 01:15:43.452003 kernel: audit: type=1130 audit(1788484543.442:18): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=parse-ip-for-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.449643 systemd[1]: Starting systemd-networkd.service - Network Configuration... Sep 4 01:15:43.442000 audit: BPF prog-id=9 op=LOAD Sep 4 01:15:43.458866 kernel: audit: type=1334 audit(1788484543.442:19): prog-id=9 op=LOAD Sep 4 01:15:43.472621 systemd[1]: Finished dracut-pre-trigger.service - dracut pre-trigger hook. Sep 4 01:15:43.474000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.481862 kernel: audit: type=1130 audit(1788484543.474:20): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.481963 systemd[1]: Starting systemd-udev-trigger.service - Coldplug All udev Devices... Sep 4 01:15:43.503804 systemd-networkd[1477]: lo: Link UP Sep 4 01:15:43.505092 systemd-networkd[1477]: lo: Gained carrier Sep 4 01:15:43.506992 systemd[1]: Started systemd-networkd.service - Network Configuration. Sep 4 01:15:43.511000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.512997 systemd[1]: Reached target network.target - Network. Sep 4 01:15:43.520941 kernel: audit: type=1130 audit(1788484543.511:21): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.534289 systemd[1]: Finished systemd-udev-trigger.service - Coldplug All udev Devices. Sep 4 01:15:43.537000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udev-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.546863 kernel: audit: type=1130 audit(1788484543.537:22): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udev-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.575462 systemd[1]: Starting dracut-initqueue.service - dracut initqueue hook... Sep 4 01:15:43.642906 kernel: hv_vmbus: registering driver hv_netvsc Sep 4 01:15:43.651710 kernel: hv_netvsc f8615163-0000-1000-2000-70a8a57fdb30 (unnamed net_device) (uninitialized): VF slot 1 added Sep 4 01:15:43.666566 systemd[1]: systemd-vconsole-setup.service: Deactivated successfully. Sep 4 01:15:43.672416 kernel: cryptd: max_cpu_qlen set to 1000 Sep 4 01:15:43.666722 systemd[1]: Stopped systemd-vconsole-setup.service - Virtual Console Setup. Sep 4 01:15:43.679983 kernel: audit: type=1131 audit(1788484543.669:23): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.669000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.668386 systemd-networkd[1477]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Sep 4 01:15:43.668391 systemd-networkd[1477]: eth0: Configuring with /usr/lib/systemd/network/zz-default.network. Sep 4 01:15:43.669197 systemd-networkd[1477]: eth0: Link UP Sep 4 01:15:43.670617 systemd-networkd[1477]: eth0: Gained carrier Sep 4 01:15:43.693283 kernel: hv_storvsc f8b3781a-1e82-4818-a1c3-63d806ec15bb: tag#44 cmd 0x85 status: scsi 0x2 srb 0x6 hv 0xc0000001 Sep 4 01:15:43.670632 systemd-networkd[1477]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Sep 4 01:15:43.670831 systemd[1]: Stopping systemd-vconsole-setup.service - Virtual Console Setup... Sep 4 01:15:43.692608 systemd[1]: Starting systemd-vconsole-setup.service - Virtual Console Setup... Sep 4 01:15:43.692869 systemd-networkd[1477]: eth0: DHCPv4 address 10.0.0.35/24, gateway 10.0.0.1 acquired from 168.63.129.16 Sep 4 01:15:43.716859 kernel: AES CTR mode by8 optimization enabled Sep 4 01:15:43.722657 systemd[1]: Finished systemd-vconsole-setup.service - Virtual Console Setup. Sep 4 01:15:43.724000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.729859 kernel: audit: type=1130 audit(1788484543.724:24): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:43.839964 kernel: nvme nvme0: using unchecked data buffer Sep 4 01:15:43.938944 systemd[1]: Found device dev-disk-by\x2dpartlabel-USR\x2dA.device - MSFT NVMe Accelerator v1.0 USR-A. Sep 4 01:15:43.942658 systemd[1]: Starting disk-uuid.service - Generate new UUID for disk GPT if necessary... Sep 4 01:15:44.037624 systemd[1]: Found device dev-disk-by\x2dlabel-OEM.device - MSFT NVMe Accelerator v1.0 OEM. Sep 4 01:15:44.052178 systemd[1]: Found device dev-disk-by\x2dlabel-EFI\x2dSYSTEM.device - MSFT NVMe Accelerator v1.0 EFI-SYSTEM. Sep 4 01:15:44.064194 systemd[1]: Found device dev-disk-by\x2dlabel-ROOT.device - MSFT NVMe Accelerator v1.0 ROOT. Sep 4 01:15:44.361979 systemd[1]: Finished dracut-initqueue.service - dracut initqueue hook. Sep 4 01:15:44.361000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-initqueue comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:44.367133 systemd[1]: Reached target remote-fs-pre.target - Preparation for Remote File Systems. Sep 4 01:15:44.371046 kernel: audit: type=1130 audit(1788484544.361:25): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-initqueue comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:44.369509 systemd[1]: Reached target remote-cryptsetup.target - Remote Encrypted Volumes. Sep 4 01:15:44.373385 systemd[1]: Reached target remote-fs.target - Remote File Systems. Sep 4 01:15:44.378651 systemd[1]: Starting dracut-pre-mount.service - dracut pre-mount hook... Sep 4 01:15:44.421122 systemd[1]: Finished dracut-pre-mount.service - dracut pre-mount hook. Sep 4 01:15:44.428856 kernel: audit: type=1130 audit(1788484544.421:26): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:44.421000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:44.668787 kernel: hv_pci 00000001-7870-47b5-b203-907d12ca697e: PCI VMBus probing: Using version 0x10004 Sep 4 01:15:44.669065 kernel: hv_pci 00000001-7870-47b5-b203-907d12ca697e: PCI host bridge to bus 7870:00 Sep 4 01:15:44.671331 kernel: pci_bus 7870:00: root bus resource [mem 0xfc2000000-0xfc4007fff window] Sep 4 01:15:44.673914 kernel: pci_bus 7870:00: No busn resource found for root bus, will use [bus 00-ff] Sep 4 01:15:44.677979 kernel: pci 7870:00:00.0: [1414:00ba] type 00 class 0x020000 PCIe Endpoint Sep 4 01:15:44.680967 kernel: pci 7870:00:00.0: BAR 0 [mem 0xfc2000000-0xfc3ffffff 64bit pref] Sep 4 01:15:44.686183 kernel: pci 7870:00:00.0: BAR 4 [mem 0xfc4000000-0xfc4007fff 64bit pref] Sep 4 01:15:44.686249 kernel: pci 7870:00:00.0: enabling Extended Tags Sep 4 01:15:44.699435 kernel: pci_bus 7870:00: busn_res: [bus 00-ff] end is updated to 00 Sep 4 01:15:44.699625 kernel: pci 7870:00:00.0: BAR 0 [mem 0xfc2000000-0xfc3ffffff 64bit pref]: assigned Sep 4 01:15:44.702962 kernel: pci 7870:00:00.0: BAR 4 [mem 0xfc4000000-0xfc4007fff 64bit pref]: assigned Sep 4 01:15:44.726754 kernel: mana 7870:00:00.0: enabling device (0000 -> 0002) Sep 4 01:15:44.736854 kernel: mana 7870:00:00.0: Microsoft Azure Network Adapter protocol version: 0.1.1 Sep 4 01:15:44.739152 kernel: hv_netvsc f8615163-0000-1000-2000-70a8a57fdb30 eth0: VF registering: eth1 Sep 4 01:15:44.739328 kernel: mana 7870:00:00.0 eth1: joined to eth0 Sep 4 01:15:44.743528 systemd-networkd[1477]: eth1: Interface name change detected, renamed to enP30832s1. Sep 4 01:15:44.745925 kernel: mana 7870:00:00.0 enP30832s1: renamed from eth1 Sep 4 01:15:44.844868 kernel: mana 7870:00:00.0 enP30832s1: Configured vPort 0 PD 18 DB 16 Sep 4 01:15:44.848373 kernel: mana 7870:00:00.0 enP30832s1: Configured steering vPort 0 entries 64 Sep 4 01:15:44.848679 kernel: hv_netvsc f8615163-0000-1000-2000-70a8a57fdb30 eth0: Data path switched to VF: enP30832s1 Sep 4 01:15:44.848981 systemd-networkd[1477]: enP30832s1: Link UP Sep 4 01:15:44.849868 systemd-networkd[1477]: enP30832s1: Gained carrier Sep 4 01:15:44.857904 systemd-networkd[1477]: eth0: Gained IPv6LL Sep 4 01:15:45.431623 disk-uuid[1653]: Warning: The kernel is still using the old partition table. Sep 4 01:15:45.431623 disk-uuid[1653]: The new table will be used at the next reboot or after you Sep 4 01:15:45.431623 disk-uuid[1653]: run partprobe(8) or kpartx(8) Sep 4 01:15:45.431623 disk-uuid[1653]: The operation has completed successfully. Sep 4 01:15:45.442000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=disk-uuid comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:45.442000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=disk-uuid comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:45.440635 systemd[1]: disk-uuid.service: Deactivated successfully. Sep 4 01:15:45.440729 systemd[1]: Finished disk-uuid.service - Generate new UUID for disk GPT if necessary. Sep 4 01:15:45.445293 systemd[1]: Starting ignition-setup.service - Ignition (setup)... Sep 4 01:15:45.507924 kernel: BTRFS: device label OEM devid 1 transid 12 /dev/nvme0n1p6 (259:5) scanned by mount (1699) Sep 4 01:15:45.508123 kernel: BTRFS info (device nvme0n1p6): first mount of filesystem 2fb02e56-8a2d-4991-9f4d-862e2ca2333b Sep 4 01:15:45.509612 kernel: BTRFS info (device nvme0n1p6): using crc32c (crc32c-intel) checksum algorithm Sep 4 01:15:45.545299 kernel: BTRFS info (device nvme0n1p6): enabling ssd optimizations Sep 4 01:15:45.545399 kernel: BTRFS info (device nvme0n1p6): turning on async discard Sep 4 01:15:45.546311 kernel: BTRFS info (device nvme0n1p6): enabling free space tree Sep 4 01:15:45.551856 kernel: BTRFS info (device nvme0n1p6): last unmount of filesystem 2fb02e56-8a2d-4991-9f4d-862e2ca2333b Sep 4 01:15:45.552645 systemd[1]: Finished ignition-setup.service - Ignition (setup). Sep 4 01:15:45.552000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:45.555592 systemd[1]: Starting ignition-fetch-offline.service - Ignition (fetch-offline)... Sep 4 01:15:46.598394 ignition[1717]: Ignition 2.24.0 Sep 4 01:15:46.598408 ignition[1717]: Stage: fetch-offline Sep 4 01:15:46.599979 systemd[1]: Finished ignition-fetch-offline.service - Ignition (fetch-offline). Sep 4 01:15:46.598528 ignition[1717]: no configs at "/usr/lib/ignition/base.d" Sep 4 01:15:46.601000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-fetch-offline comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:46.603913 systemd[1]: Starting ignition-fetch.service - Ignition (fetch)... Sep 4 01:15:46.598538 ignition[1717]: no config dir at "/usr/lib/ignition/base.platform.d/azure" Sep 4 01:15:46.598637 ignition[1717]: parsed url from cmdline: "" Sep 4 01:15:46.598639 ignition[1717]: no config URL provided Sep 4 01:15:46.598644 ignition[1717]: reading system config file "/usr/lib/ignition/user.ign" Sep 4 01:15:46.598651 ignition[1717]: no config at "/usr/lib/ignition/user.ign" Sep 4 01:15:46.598655 ignition[1717]: failed to fetch config: resource requires networking Sep 4 01:15:46.598812 ignition[1717]: Ignition finished successfully Sep 4 01:15:46.624337 ignition[1724]: Ignition 2.24.0 Sep 4 01:15:46.624348 ignition[1724]: Stage: fetch Sep 4 01:15:46.624573 ignition[1724]: no configs at "/usr/lib/ignition/base.d" Sep 4 01:15:46.624581 ignition[1724]: no config dir at "/usr/lib/ignition/base.platform.d/azure" Sep 4 01:15:46.624660 ignition[1724]: parsed url from cmdline: "" Sep 4 01:15:46.624663 ignition[1724]: no config URL provided Sep 4 01:15:46.624667 ignition[1724]: reading system config file "/usr/lib/ignition/user.ign" Sep 4 01:15:46.624672 ignition[1724]: no config at "/usr/lib/ignition/user.ign" Sep 4 01:15:46.624692 ignition[1724]: GET http://169.254.169.254/metadata/instance/compute/userData?api-version=2021-01-01&format=text: attempt #1 Sep 4 01:15:46.694252 ignition[1724]: GET result: OK Sep 4 01:15:46.694301 ignition[1724]: config has been read from IMDS userdata Sep 4 01:15:46.694313 ignition[1724]: parsing config with SHA512: 04750454ffa4ab4b49dca9e1bd7cb6cc1ac5819ef053efa4ea633fe56ebd5b0fae57c85c19e668e4e751801314d57e7dd0fda1adca8ff2d02e181990e7291cb8 Sep 4 01:15:46.700320 unknown[1724]: fetched base config from "system" Sep 4 01:15:46.700331 unknown[1724]: fetched base config from "system" Sep 4 01:15:46.700492 ignition[1724]: fetch: fetch complete Sep 4 01:15:46.700337 unknown[1724]: fetched user config from "azure" Sep 4 01:15:46.702000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-fetch comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:46.700496 ignition[1724]: fetch: fetch passed Sep 4 01:15:46.702975 systemd[1]: Finished ignition-fetch.service - Ignition (fetch). Sep 4 01:15:46.700535 ignition[1724]: Ignition finished successfully Sep 4 01:15:46.706295 systemd[1]: Starting ignition-kargs.service - Ignition (kargs)... Sep 4 01:15:46.727479 ignition[1730]: Ignition 2.24.0 Sep 4 01:15:46.727490 ignition[1730]: Stage: kargs Sep 4 01:15:46.727735 ignition[1730]: no configs at "/usr/lib/ignition/base.d" Sep 4 01:15:46.732000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-kargs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:46.730325 systemd[1]: Finished ignition-kargs.service - Ignition (kargs). Sep 4 01:15:46.727742 ignition[1730]: no config dir at "/usr/lib/ignition/base.platform.d/azure" Sep 4 01:15:46.734753 systemd[1]: Starting ignition-disks.service - Ignition (disks)... Sep 4 01:15:46.728319 ignition[1730]: kargs: kargs passed Sep 4 01:15:46.728354 ignition[1730]: Ignition finished successfully Sep 4 01:15:46.755653 ignition[1736]: Ignition 2.24.0 Sep 4 01:15:46.755665 ignition[1736]: Stage: disks Sep 4 01:15:46.755940 ignition[1736]: no configs at "/usr/lib/ignition/base.d" Sep 4 01:15:46.759000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-disks comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:46.758349 systemd[1]: Finished ignition-disks.service - Ignition (disks). Sep 4 01:15:46.755949 ignition[1736]: no config dir at "/usr/lib/ignition/base.platform.d/azure" Sep 4 01:15:46.761586 systemd[1]: Reached target initrd-root-device.target - Initrd Root Device. Sep 4 01:15:46.756557 ignition[1736]: disks: disks passed Sep 4 01:15:46.763224 systemd[1]: Reached target local-fs-pre.target - Preparation for Local File Systems. Sep 4 01:15:46.756593 ignition[1736]: Ignition finished successfully Sep 4 01:15:46.767693 systemd[1]: Reached target local-fs.target - Local File Systems. Sep 4 01:15:46.773392 systemd[1]: Reached target sysinit.target - System Initialization. Sep 4 01:15:46.779793 systemd[1]: Reached target basic.target - Basic System. Sep 4 01:15:46.782753 systemd[1]: Starting systemd-fsck-root.service - File System Check on /dev/disk/by-label/ROOT... Sep 4 01:15:46.889022 systemd-fsck[1744]: ROOT: clean, 15/6361680 files, 408771/6359552 blocks Sep 4 01:15:46.894209 systemd[1]: Finished systemd-fsck-root.service - File System Check on /dev/disk/by-label/ROOT. Sep 4 01:15:46.896000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-fsck-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:46.898800 systemd[1]: Mounting sysroot.mount - /sysroot... Sep 4 01:15:47.205861 kernel: EXT4-fs (nvme0n1p9): mounted filesystem e07d5b52-8233-4881-9fb4-a4b01abf7911 r/w with ordered data mode. Quota mode: none. Sep 4 01:15:47.206749 systemd[1]: Mounted sysroot.mount - /sysroot. Sep 4 01:15:47.209043 systemd[1]: Reached target initrd-root-fs.target - Initrd Root File System. Sep 4 01:15:47.249485 systemd[1]: Mounting sysroot-oem.mount - /sysroot/oem... Sep 4 01:15:47.251914 systemd[1]: Mounting sysroot-usr.mount - /sysroot/usr... Sep 4 01:15:47.260973 systemd[1]: Starting flatcar-metadata-hostname.service - Flatcar Metadata Hostname Agent... Sep 4 01:15:47.264807 systemd[1]: ignition-remount-sysroot.service - Remount /sysroot read-write for Ignition was skipped because of an unmet condition check (ConditionPathIsReadWrite=!/sysroot). Sep 4 01:15:47.264872 systemd[1]: Reached target ignition-diskful.target - Ignition Boot Disk Setup. Sep 4 01:15:47.269972 systemd[1]: Mounted sysroot-usr.mount - /sysroot/usr. Sep 4 01:15:47.275021 kernel: BTRFS: device label OEM devid 1 transid 12 /dev/nvme0n1p6 (259:5) scanned by mount (1753) Sep 4 01:15:47.276957 systemd[1]: Starting initrd-setup-root.service - Root filesystem setup... Sep 4 01:15:47.283968 kernel: BTRFS info (device nvme0n1p6): first mount of filesystem 2fb02e56-8a2d-4991-9f4d-862e2ca2333b Sep 4 01:15:47.283987 kernel: BTRFS info (device nvme0n1p6): using crc32c (crc32c-intel) checksum algorithm Sep 4 01:15:47.294319 kernel: BTRFS info (device nvme0n1p6): enabling ssd optimizations Sep 4 01:15:47.294347 kernel: BTRFS info (device nvme0n1p6): turning on async discard Sep 4 01:15:47.296150 kernel: BTRFS info (device nvme0n1p6): enabling free space tree Sep 4 01:15:47.297772 systemd[1]: Mounted sysroot-oem.mount - /sysroot/oem. Sep 4 01:15:47.858569 coreos-metadata[1755]: Sep 04 01:15:47.858 INFO Fetching http://168.63.129.16/?comp=versions: Attempt #1 Sep 4 01:15:47.861642 coreos-metadata[1755]: Sep 04 01:15:47.861 INFO Fetch successful Sep 4 01:15:47.863922 coreos-metadata[1755]: Sep 04 01:15:47.862 INFO Fetching http://169.254.169.254/metadata/instance/compute/name?api-version=2017-08-01&format=text: Attempt #1 Sep 4 01:15:47.871149 coreos-metadata[1755]: Sep 04 01:15:47.871 INFO Fetch successful Sep 4 01:15:47.887005 coreos-metadata[1755]: Sep 04 01:15:47.886 INFO wrote hostname ci-4593.2.5-n-471707002a to /sysroot/etc/hostname Sep 4 01:15:47.889668 systemd[1]: Finished flatcar-metadata-hostname.service - Flatcar Metadata Hostname Agent. Sep 4 01:15:47.891000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=flatcar-metadata-hostname comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:48.981836 systemd[1]: Finished initrd-setup-root.service - Root filesystem setup. Sep 4 01:15:48.986258 kernel: kauditd_printk_skb: 9 callbacks suppressed Sep 4 01:15:48.986286 kernel: audit: type=1130 audit(1788484548.980:36): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:48.980000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:48.989289 systemd[1]: Starting ignition-mount.service - Ignition (mount)... Sep 4 01:15:48.995956 systemd[1]: Starting sysroot-boot.service - /sysroot/boot... Sep 4 01:15:49.026806 systemd[1]: sysroot-oem.mount: Deactivated successfully. Sep 4 01:15:49.028943 kernel: BTRFS info (device nvme0n1p6): last unmount of filesystem 2fb02e56-8a2d-4991-9f4d-862e2ca2333b Sep 4 01:15:49.039095 systemd[1]: Finished sysroot-boot.service - /sysroot/boot. Sep 4 01:15:49.040000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=sysroot-boot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.045921 kernel: audit: type=1130 audit(1788484549.040:37): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=sysroot-boot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.051689 ignition[1857]: INFO : Ignition 2.24.0 Sep 4 01:15:49.051689 ignition[1857]: INFO : Stage: mount Sep 4 01:15:49.054000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.058586 ignition[1857]: INFO : no configs at "/usr/lib/ignition/base.d" Sep 4 01:15:49.058586 ignition[1857]: INFO : no config dir at "/usr/lib/ignition/base.platform.d/azure" Sep 4 01:15:49.058586 ignition[1857]: INFO : mount: mount passed Sep 4 01:15:49.058586 ignition[1857]: INFO : Ignition finished successfully Sep 4 01:15:49.071455 kernel: audit: type=1130 audit(1788484549.054:38): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.053726 systemd[1]: Finished ignition-mount.service - Ignition (mount). Sep 4 01:15:49.062977 systemd[1]: Starting ignition-files.service - Ignition (files)... Sep 4 01:15:49.072052 systemd[1]: Mounting sysroot-oem.mount - /sysroot/oem... Sep 4 01:15:49.097869 kernel: BTRFS: device label OEM devid 1 transid 12 /dev/nvme0n1p6 (259:5) scanned by mount (1866) Sep 4 01:15:49.100861 kernel: BTRFS info (device nvme0n1p6): first mount of filesystem 2fb02e56-8a2d-4991-9f4d-862e2ca2333b Sep 4 01:15:49.100902 kernel: BTRFS info (device nvme0n1p6): using crc32c (crc32c-intel) checksum algorithm Sep 4 01:15:49.107115 kernel: BTRFS info (device nvme0n1p6): enabling ssd optimizations Sep 4 01:15:49.107155 kernel: BTRFS info (device nvme0n1p6): turning on async discard Sep 4 01:15:49.107218 kernel: BTRFS info (device nvme0n1p6): enabling free space tree Sep 4 01:15:49.109368 systemd[1]: Mounted sysroot-oem.mount - /sysroot/oem. Sep 4 01:15:49.131896 ignition[1882]: INFO : Ignition 2.24.0 Sep 4 01:15:49.131896 ignition[1882]: INFO : Stage: files Sep 4 01:15:49.134947 ignition[1882]: INFO : no configs at "/usr/lib/ignition/base.d" Sep 4 01:15:49.134947 ignition[1882]: INFO : no config dir at "/usr/lib/ignition/base.platform.d/azure" Sep 4 01:15:49.134947 ignition[1882]: DEBUG : files: compiled without relabeling support, skipping Sep 4 01:15:49.134947 ignition[1882]: INFO : files: ensureUsers: op(1): [started] creating or modifying user "core" Sep 4 01:15:49.134947 ignition[1882]: DEBUG : files: ensureUsers: op(1): executing: "usermod" "--root" "/sysroot" "core" Sep 4 01:15:49.204252 ignition[1882]: INFO : files: ensureUsers: op(1): [finished] creating or modifying user "core" Sep 4 01:15:49.206222 ignition[1882]: INFO : files: ensureUsers: op(2): [started] adding ssh keys to user "core" Sep 4 01:15:49.208921 ignition[1882]: INFO : files: ensureUsers: op(2): [finished] adding ssh keys to user "core" Sep 4 01:15:49.206510 unknown[1882]: wrote ssh authorized keys file for user: core Sep 4 01:15:49.236500 ignition[1882]: INFO : files: createFilesystemsFiles: createFiles: op(3): [started] writing file "/sysroot/etc/flatcar/update.conf" Sep 4 01:15:49.240952 ignition[1882]: INFO : files: createFilesystemsFiles: createFiles: op(3): [finished] writing file "/sysroot/etc/flatcar/update.conf" Sep 4 01:15:49.240952 ignition[1882]: INFO : files: createResultFile: createFiles: op(4): [started] writing file "/sysroot/etc/.ignition-result.json" Sep 4 01:15:49.240952 ignition[1882]: INFO : files: createResultFile: createFiles: op(4): [finished] writing file "/sysroot/etc/.ignition-result.json" Sep 4 01:15:49.240952 ignition[1882]: INFO : files: files passed Sep 4 01:15:49.240952 ignition[1882]: INFO : Ignition finished successfully Sep 4 01:15:49.260615 kernel: audit: type=1130 audit(1788484549.245:39): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-files comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.245000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-files comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.239888 systemd[1]: Finished ignition-files.service - Ignition (files). Sep 4 01:15:49.247957 systemd[1]: Starting ignition-quench.service - Ignition (record completion)... Sep 4 01:15:49.264490 systemd[1]: Starting initrd-setup-root-after-ignition.service - Root filesystem completion... Sep 4 01:15:49.273110 systemd[1]: ignition-quench.service: Deactivated successfully. Sep 4 01:15:49.274946 systemd[1]: Finished ignition-quench.service - Ignition (record completion). Sep 4 01:15:49.276000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-quench comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.276000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-quench comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.284909 kernel: audit: type=1130 audit(1788484549.276:40): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-quench comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.285037 kernel: audit: type=1131 audit(1788484549.276:41): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-quench comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.303647 initrd-setup-root-after-ignition[1914]: grep: /sysroot/etc/flatcar/enabled-sysext.conf: No such file or directory Sep 4 01:15:49.303647 initrd-setup-root-after-ignition[1914]: grep: /sysroot/usr/share/flatcar/enabled-sysext.conf: No such file or directory Sep 4 01:15:49.309957 initrd-setup-root-after-ignition[1918]: grep: /sysroot/etc/flatcar/enabled-sysext.conf: No such file or directory Sep 4 01:15:49.309073 systemd[1]: Finished initrd-setup-root-after-ignition.service - Root filesystem completion. Sep 4 01:15:49.314000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root-after-ignition comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.316408 systemd[1]: Reached target ignition-complete.target - Ignition Complete. Sep 4 01:15:49.323146 kernel: audit: type=1130 audit(1788484549.314:42): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root-after-ignition comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.325539 systemd[1]: Starting initrd-parse-etc.service - Mountpoints Configured in the Real Root... Sep 4 01:15:49.363438 systemd[1]: initrd-parse-etc.service: Deactivated successfully. Sep 4 01:15:49.363531 systemd[1]: Finished initrd-parse-etc.service - Mountpoints Configured in the Real Root. Sep 4 01:15:49.373000 kernel: audit: type=1130 audit(1788484549.364:43): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-parse-etc comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.373032 kernel: audit: type=1131 audit(1788484549.368:44): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-parse-etc comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.364000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-parse-etc comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.368000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-parse-etc comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.369720 systemd[1]: Reached target initrd-fs.target - Initrd File Systems. Sep 4 01:15:49.373860 systemd[1]: Reached target initrd.target - Initrd Default Target. Sep 4 01:15:49.374140 systemd[1]: dracut-mount.service - dracut mount hook was skipped because no trigger condition checks were met. Sep 4 01:15:49.374891 systemd[1]: Starting dracut-pre-pivot.service - dracut pre-pivot and cleanup hook... Sep 4 01:15:49.393113 systemd[1]: Finished dracut-pre-pivot.service - dracut pre-pivot and cleanup hook. Sep 4 01:15:49.393000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-pivot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.398858 kernel: audit: type=1130 audit(1788484549.393:45): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-pivot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.399250 systemd[1]: Starting initrd-cleanup.service - Cleaning Up and Shutting Down Daemons... Sep 4 01:15:49.414242 systemd[1]: Unnecessary job was removed for dev-mapper-usr.device - /dev/mapper/usr. Sep 4 01:15:49.414446 systemd[1]: Stopped target nss-lookup.target - Host and Network Name Lookups. Sep 4 01:15:49.416963 systemd[1]: Stopped target remote-cryptsetup.target - Remote Encrypted Volumes. Sep 4 01:15:49.419436 systemd[1]: Stopped target timers.target - Timer Units. Sep 4 01:15:49.425000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-pivot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.423016 systemd[1]: dracut-pre-pivot.service: Deactivated successfully. Sep 4 01:15:49.423148 systemd[1]: Stopped dracut-pre-pivot.service - dracut pre-pivot and cleanup hook. Sep 4 01:15:49.431999 systemd[1]: Stopped target initrd.target - Initrd Default Target. Sep 4 01:15:49.433850 systemd[1]: Stopped target basic.target - Basic System. Sep 4 01:15:49.436173 systemd[1]: Stopped target ignition-complete.target - Ignition Complete. Sep 4 01:15:49.441238 systemd[1]: Stopped target ignition-diskful.target - Ignition Boot Disk Setup. Sep 4 01:15:49.445439 systemd[1]: Stopped target initrd-root-device.target - Initrd Root Device. Sep 4 01:15:49.448338 systemd[1]: Stopped target initrd-usr-fs.target - Initrd /usr File System. Sep 4 01:15:49.449696 systemd[1]: Stopped target remote-fs.target - Remote File Systems. Sep 4 01:15:49.449897 systemd[1]: Stopped target remote-fs-pre.target - Preparation for Remote File Systems. Sep 4 01:15:49.450143 systemd[1]: Stopped target sysinit.target - System Initialization. Sep 4 01:15:49.456006 systemd[1]: Stopped target local-fs.target - Local File Systems. Sep 4 01:15:49.464000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.459970 systemd[1]: Stopped target swap.target - Swaps. Sep 4 01:15:49.462428 systemd[1]: dracut-pre-mount.service: Deactivated successfully. Sep 4 01:15:49.462555 systemd[1]: Stopped dracut-pre-mount.service - dracut pre-mount hook. Sep 4 01:15:49.466431 systemd[1]: Stopped target cryptsetup.target - Local Encrypted Volumes. Sep 4 01:15:49.471428 systemd[1]: Stopped target cryptsetup-pre.target - Local Encrypted Volumes (Pre). Sep 4 01:15:49.473934 systemd[1]: clevis-luks-askpass.path: Deactivated successfully. Sep 4 01:15:49.475059 systemd[1]: Stopped clevis-luks-askpass.path - Forward Password Requests to Clevis Directory Watch. Sep 4 01:15:49.483000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-initqueue comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.480623 systemd[1]: dracut-initqueue.service: Deactivated successfully. Sep 4 01:15:49.480748 systemd[1]: Stopped dracut-initqueue.service - dracut initqueue hook. Sep 4 01:15:49.495915 systemd[1]: initrd-setup-root-after-ignition.service: Deactivated successfully. Sep 4 01:15:49.499000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root-after-ignition comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.496062 systemd[1]: Stopped initrd-setup-root-after-ignition.service - Root filesystem completion. Sep 4 01:15:49.501000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-files comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.500326 systemd[1]: ignition-files.service: Deactivated successfully. Sep 4 01:15:49.505000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=flatcar-metadata-hostname comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.500437 systemd[1]: Stopped ignition-files.service - Ignition (files). Sep 4 01:15:49.503367 systemd[1]: flatcar-metadata-hostname.service: Deactivated successfully. Sep 4 01:15:49.503673 systemd[1]: Stopped flatcar-metadata-hostname.service - Flatcar Metadata Hostname Agent. Sep 4 01:15:49.507921 systemd[1]: Stopping ignition-mount.service - Ignition (mount)... Sep 4 01:15:49.512218 systemd[1]: kmod-static-nodes.service: Deactivated successfully. Sep 4 01:15:49.512406 systemd[1]: Stopped kmod-static-nodes.service - Create List of Static Device Nodes. Sep 4 01:15:49.522000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=kmod-static-nodes comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.525022 systemd[1]: Stopping sysroot-boot.service - /sysroot/boot... Sep 4 01:15:49.529338 systemd[1]: systemd-tmpfiles-setup.service: Deactivated successfully. Sep 4 01:15:49.529921 systemd[1]: Stopped systemd-tmpfiles-setup.service - Create System Files and Directories. Sep 4 01:15:49.533000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.535153 systemd[1]: systemd-udev-trigger.service: Deactivated successfully. Sep 4 01:15:49.535272 systemd[1]: Stopped systemd-udev-trigger.service - Coldplug All udev Devices. Sep 4 01:15:49.536000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udev-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.541972 ignition[1938]: INFO : Ignition 2.24.0 Sep 4 01:15:49.541972 ignition[1938]: INFO : Stage: umount Sep 4 01:15:49.541972 ignition[1938]: INFO : no configs at "/usr/lib/ignition/base.d" Sep 4 01:15:49.541972 ignition[1938]: INFO : no config dir at "/usr/lib/ignition/base.platform.d/azure" Sep 4 01:15:49.541972 ignition[1938]: INFO : umount: umount passed Sep 4 01:15:49.541972 ignition[1938]: INFO : Ignition finished successfully Sep 4 01:15:49.542000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.538247 systemd[1]: dracut-pre-trigger.service: Deactivated successfully. Sep 4 01:15:49.555000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-mount comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.538357 systemd[1]: Stopped dracut-pre-trigger.service - dracut pre-trigger hook. Sep 4 01:15:49.553790 systemd[1]: ignition-mount.service: Deactivated successfully. Sep 4 01:15:49.553892 systemd[1]: Stopped ignition-mount.service - Ignition (mount). Sep 4 01:15:49.563627 systemd[1]: ignition-disks.service: Deactivated successfully. Sep 4 01:15:49.564828 systemd[1]: Stopped ignition-disks.service - Ignition (disks). Sep 4 01:15:49.564000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-disks comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.566083 systemd[1]: ignition-kargs.service: Deactivated successfully. Sep 4 01:15:49.566132 systemd[1]: Stopped ignition-kargs.service - Ignition (kargs). Sep 4 01:15:49.573000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-kargs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.574941 systemd[1]: ignition-fetch.service: Deactivated successfully. Sep 4 01:15:49.574994 systemd[1]: Stopped ignition-fetch.service - Ignition (fetch). Sep 4 01:15:49.579000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-fetch comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.580364 systemd[1]: Stopped target network.target - Network. Sep 4 01:15:49.584178 systemd[1]: ignition-fetch-offline.service: Deactivated successfully. Sep 4 01:15:49.585196 systemd[1]: Stopped ignition-fetch-offline.service - Ignition (fetch-offline). Sep 4 01:15:49.585000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-fetch-offline comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.587276 systemd[1]: Stopped target paths.target - Path Units. Sep 4 01:15:49.592887 systemd[1]: systemd-ask-password-console.path: Deactivated successfully. Sep 4 01:15:49.594883 systemd[1]: Stopped systemd-ask-password-console.path - Dispatch Password Requests to Console Directory Watch. Sep 4 01:15:49.597684 systemd[1]: Stopped target slices.target - Slice Units. Sep 4 01:15:49.599997 systemd[1]: Stopped target sockets.target - Socket Units. Sep 4 01:15:49.606925 systemd[1]: iscsid.socket: Deactivated successfully. Sep 4 01:15:49.606968 systemd[1]: Closed iscsid.socket - Open-iSCSI iscsid Socket. Sep 4 01:15:49.610215 systemd[1]: iscsiuio.socket: Deactivated successfully. Sep 4 01:15:49.610255 systemd[1]: Closed iscsiuio.socket - Open-iSCSI iscsiuio Socket. Sep 4 01:15:49.613483 systemd[1]: systemd-journald-audit.socket: Deactivated successfully. Sep 4 01:15:49.615000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.613511 systemd[1]: Closed systemd-journald-audit.socket - Journal Audit Socket. Sep 4 01:15:49.614778 systemd[1]: ignition-setup.service: Deactivated successfully. Sep 4 01:15:49.620000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=ignition-setup-pre comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.614823 systemd[1]: Stopped ignition-setup.service - Ignition (setup). Sep 4 01:15:49.618258 systemd[1]: ignition-setup-pre.service: Deactivated successfully. Sep 4 01:15:49.619470 systemd[1]: Stopped ignition-setup-pre.service - Ignition env setup. Sep 4 01:15:49.622419 systemd[1]: Stopping systemd-networkd.service - Network Configuration... Sep 4 01:15:49.626710 systemd[1]: Stopping systemd-resolved.service - Network Name Resolution... Sep 4 01:15:49.638000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-cleanup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.638000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-cleanup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.634008 systemd[1]: sysroot-boot.mount: Deactivated successfully. Sep 4 01:15:49.642000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-resolved comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.634571 systemd[1]: initrd-cleanup.service: Deactivated successfully. Sep 4 01:15:49.647000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.634642 systemd[1]: Finished initrd-cleanup.service - Cleaning Up and Shutting Down Daemons. Sep 4 01:15:49.649000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=sysroot-boot comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.640225 systemd[1]: systemd-resolved.service: Deactivated successfully. Sep 4 01:15:49.652000 audit: BPF prog-id=9 op=UNLOAD Sep 4 01:15:49.652000 audit: BPF prog-id=6 op=UNLOAD Sep 4 01:15:49.640320 systemd[1]: Stopped systemd-resolved.service - Network Name Resolution. Sep 4 01:15:49.644948 systemd[1]: systemd-networkd.service: Deactivated successfully. Sep 4 01:15:49.645021 systemd[1]: Stopped systemd-networkd.service - Network Configuration. Sep 4 01:15:49.649725 systemd[1]: sysroot-boot.service: Deactivated successfully. Sep 4 01:15:49.649855 systemd[1]: Stopped sysroot-boot.service - /sysroot/boot. Sep 4 01:15:49.653726 systemd[1]: Stopped target network-pre.target - Preparation for Network. Sep 4 01:15:49.657177 systemd[1]: systemd-networkd.socket: Deactivated successfully. Sep 4 01:15:49.657205 systemd[1]: Closed systemd-networkd.socket - Network Service Netlink Socket. Sep 4 01:15:49.658963 systemd[1]: initrd-setup-root.service: Deactivated successfully. Sep 4 01:15:49.660751 systemd[1]: Stopped initrd-setup-root.service - Root filesystem setup. Sep 4 01:15:49.669000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-setup-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.671605 systemd[1]: Stopping network-cleanup.service - Network Cleanup... Sep 4 01:15:49.673497 systemd[1]: parse-ip-for-networkd.service: Deactivated successfully. Sep 4 01:15:49.675000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=parse-ip-for-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.674948 systemd[1]: Stopped parse-ip-for-networkd.service - Write systemd-networkd units from cmdline. Sep 4 01:15:49.677683 systemd[1]: systemd-sysctl.service: Deactivated successfully. Sep 4 01:15:49.677732 systemd[1]: Stopped systemd-sysctl.service - Apply Kernel Variables. Sep 4 01:15:49.678000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.678000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-modules-load comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.679387 systemd[1]: systemd-modules-load.service: Deactivated successfully. Sep 4 01:15:49.679427 systemd[1]: Stopped systemd-modules-load.service - Load Kernel Modules. Sep 4 01:15:49.679565 systemd[1]: Stopping systemd-udevd.service - Rule-based Manager for Device Events and Files... Sep 4 01:15:49.703790 systemd[1]: systemd-udevd.service: Deactivated successfully. Sep 4 01:15:49.705533 systemd[1]: Stopped systemd-udevd.service - Rule-based Manager for Device Events and Files. Sep 4 01:15:49.707000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-udevd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.710023 systemd[1]: systemd-udevd-control.socket: Deactivated successfully. Sep 4 01:15:49.710074 systemd[1]: Closed systemd-udevd-control.socket - udev Control Socket. Sep 4 01:15:49.714673 systemd[1]: systemd-udevd-kernel.socket: Deactivated successfully. Sep 4 01:15:49.715292 systemd[1]: Closed systemd-udevd-kernel.socket - udev Kernel Socket. Sep 4 01:15:49.722000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-pre-udev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.719643 systemd[1]: dracut-pre-udev.service: Deactivated successfully. Sep 4 01:15:49.719680 systemd[1]: Stopped dracut-pre-udev.service - dracut pre-udev hook. Sep 4 01:15:49.724959 systemd[1]: dracut-cmdline.service: Deactivated successfully. Sep 4 01:15:49.726166 systemd[1]: Stopped dracut-cmdline.service - dracut cmdline hook. Sep 4 01:15:49.731000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.732211 systemd[1]: dracut-cmdline-ask.service: Deactivated successfully. Sep 4 01:15:49.733465 systemd[1]: Stopped dracut-cmdline-ask.service - dracut ask for additional cmdline parameters. Sep 4 01:15:49.734000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=dracut-cmdline-ask comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.736608 systemd[1]: Starting initrd-udevadm-cleanup-db.service - Cleanup udev Database... Sep 4 01:15:49.738449 systemd[1]: systemd-network-generator.service: Deactivated successfully. Sep 4 01:15:49.741000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-network-generator comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.741000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-tmpfiles-setup-dev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.741000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.738501 systemd[1]: Stopped systemd-network-generator.service - Generate network units from Kernel command line. Sep 4 01:15:49.742021 systemd[1]: systemd-tmpfiles-setup-dev.service: Deactivated successfully. Sep 4 01:15:49.742071 systemd[1]: Stopped systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev. Sep 4 01:15:49.755000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-udevadm-cleanup-db comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.755000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=initrd-udevadm-cleanup-db comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.742452 systemd[1]: systemd-vconsole-setup.service: Deactivated successfully. Sep 4 01:15:49.742482 systemd[1]: Stopped systemd-vconsole-setup.service - Virtual Console Setup. Sep 4 01:15:49.763170 kernel: hv_netvsc f8615163-0000-1000-2000-70a8a57fdb30 eth0: Data path switched from VF: enP30832s1 Sep 4 01:15:49.763362 kernel: mana 7870:00:00.0 enP30832s1: Configured steering vPort 0 entries 64 Sep 4 01:15:49.754635 systemd[1]: initrd-udevadm-cleanup-db.service: Deactivated successfully. Sep 4 01:15:49.754720 systemd[1]: Finished initrd-udevadm-cleanup-db.service - Cleanup udev Database. Sep 4 01:15:49.767000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=network-cleanup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:49.765969 systemd[1]: network-cleanup.service: Deactivated successfully. Sep 4 01:15:49.766046 systemd[1]: Stopped network-cleanup.service - Network Cleanup. Sep 4 01:15:49.769708 systemd[1]: Reached target initrd-switch-root.target - Switch Root. Sep 4 01:15:49.772341 systemd[1]: Starting initrd-switch-root.service - Switch Root... Sep 4 01:15:49.828322 systemd[1]: Switching root. Sep 4 01:15:49.853436 systemd-journald[1097]: Journal stopped Sep 4 01:15:54.814447 systemd-journald[1097]: Received SIGTERM from PID 1 (systemd). Sep 4 01:15:54.814484 kernel: SELinux: policy capability network_peer_controls=1 Sep 4 01:15:54.814498 kernel: SELinux: policy capability open_perms=1 Sep 4 01:15:54.814507 kernel: SELinux: policy capability extended_socket_class=1 Sep 4 01:15:54.814516 kernel: SELinux: policy capability always_check_network=0 Sep 4 01:15:54.814524 kernel: SELinux: policy capability cgroup_seclabel=1 Sep 4 01:15:54.814533 kernel: SELinux: policy capability nnp_nosuid_transition=1 Sep 4 01:15:54.814542 kernel: SELinux: policy capability genfs_seclabel_symlinks=0 Sep 4 01:15:54.814552 kernel: SELinux: policy capability ioctl_skip_cloexec=0 Sep 4 01:15:54.814561 kernel: SELinux: policy capability userspace_initial_context=0 Sep 4 01:15:54.814571 systemd[1]: Successfully loaded SELinux policy in 150.833ms. Sep 4 01:15:54.814582 systemd[1]: Relabeled /dev/, /dev/shm/, /run/ in 4.312ms. Sep 4 01:15:54.814593 systemd[1]: systemd 257.9 running in system mode (+PAM +AUDIT +SELINUX -APPARMOR +IMA +IPE +SMACK +SECCOMP -GCRYPT -GNUTLS +OPENSSL -ACL +BLKID +CURL +ELFUTILS -FIDO2 +IDN2 -IDN +IPTC +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 -PWQUALITY -P11KIT -QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD -BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP -SYSVINIT +LIBARCHIVE) Sep 4 01:15:54.814624 systemd[1]: Detected virtualization microsoft. Sep 4 01:15:54.814635 systemd[1]: Detected architecture x86-64. Sep 4 01:15:54.814646 systemd[1]: Detected first boot. Sep 4 01:15:54.814656 systemd[1]: Hostname set to . Sep 4 01:15:54.814668 systemd[1]: Initializing machine ID from random generator. Sep 4 01:15:54.814678 zram_generator::config[1981]: No configuration found. Sep 4 01:15:54.814689 kernel: Guest personality initialized and is inactive Sep 4 01:15:54.814699 kernel: VMCI host device registered (name=vmci, major=10, minor=259) Sep 4 01:15:54.814708 kernel: Initialized host personality Sep 4 01:15:54.814717 kernel: NET: Registered PF_VSOCK protocol family Sep 4 01:15:54.814727 systemd[1]: Populated /etc with preset unit settings. Sep 4 01:15:54.814738 kernel: kauditd_printk_skb: 44 callbacks suppressed Sep 4 01:15:54.814749 kernel: audit: type=1334 audit(1788484554.344:90): prog-id=12 op=LOAD Sep 4 01:15:54.814758 kernel: audit: type=1334 audit(1788484554.344:91): prog-id=3 op=UNLOAD Sep 4 01:15:54.814768 kernel: audit: type=1334 audit(1788484554.344:92): prog-id=13 op=LOAD Sep 4 01:15:54.814777 kernel: audit: type=1334 audit(1788484554.344:93): prog-id=14 op=LOAD Sep 4 01:15:54.814786 kernel: audit: type=1334 audit(1788484554.344:94): prog-id=4 op=UNLOAD Sep 4 01:15:54.814797 kernel: audit: type=1334 audit(1788484554.344:95): prog-id=5 op=UNLOAD Sep 4 01:15:54.814809 kernel: audit: type=1131 audit(1788484554.347:96): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-journald comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.814819 systemd[1]: initrd-switch-root.service: Deactivated successfully. Sep 4 01:15:54.814829 kernel: audit: type=1334 audit(1788484554.359:97): prog-id=12 op=UNLOAD Sep 4 01:15:54.814868 systemd[1]: Stopped initrd-switch-root.service - Switch Root. Sep 4 01:15:54.814880 kernel: audit: type=1130 audit(1788484554.365:98): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=initrd-switch-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.814892 systemd[1]: systemd-journald.service: Scheduled restart job, restart counter is at 1. Sep 4 01:15:54.814902 kernel: audit: type=1131 audit(1788484554.365:99): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=initrd-switch-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.814915 systemd[1]: Created slice system-addon\x2dconfig.slice - Slice /system/addon-config. Sep 4 01:15:54.814926 systemd[1]: Created slice system-addon\x2drun.slice - Slice /system/addon-run. Sep 4 01:15:54.814940 systemd[1]: Created slice system-getty.slice - Slice /system/getty. Sep 4 01:15:54.814951 systemd[1]: Created slice system-modprobe.slice - Slice /system/modprobe. Sep 4 01:15:54.814964 systemd[1]: Created slice system-serial\x2dgetty.slice - Slice /system/serial-getty. Sep 4 01:15:54.814974 systemd[1]: Created slice system-system\x2dcloudinit.slice - Slice /system/system-cloudinit. Sep 4 01:15:54.814985 systemd[1]: Created slice system-systemd\x2dfsck.slice - Slice /system/systemd-fsck. Sep 4 01:15:54.814995 systemd[1]: Created slice user.slice - User and Session Slice. Sep 4 01:15:54.815005 systemd[1]: Started clevis-luks-askpass.path - Forward Password Requests to Clevis Directory Watch. Sep 4 01:15:54.815016 systemd[1]: Started systemd-ask-password-console.path - Dispatch Password Requests to Console Directory Watch. Sep 4 01:15:54.815029 systemd[1]: Started systemd-ask-password-wall.path - Forward Password Requests to Wall Directory Watch. Sep 4 01:15:54.815039 systemd[1]: Set up automount boot.automount - Boot partition Automount Point. Sep 4 01:15:54.815050 systemd[1]: Set up automount proc-sys-fs-binfmt_misc.automount - Arbitrary Executable File Formats File System Automount Point. Sep 4 01:15:54.815062 systemd[1]: Expecting device dev-disk-by\x2dlabel-OEM.device - /dev/disk/by-label/OEM... Sep 4 01:15:54.815074 systemd[1]: Expecting device dev-ttyS0.device - /dev/ttyS0... Sep 4 01:15:54.815085 systemd[1]: Reached target cryptsetup-pre.target - Local Encrypted Volumes (Pre). Sep 4 01:15:54.815099 systemd[1]: Reached target cryptsetup.target - Local Encrypted Volumes. Sep 4 01:15:54.815110 systemd[1]: Stopped target initrd-switch-root.target - Switch Root. Sep 4 01:15:54.815122 systemd[1]: Stopped target initrd-fs.target - Initrd File Systems. Sep 4 01:15:54.815133 systemd[1]: Stopped target initrd-root-fs.target - Initrd Root File System. Sep 4 01:15:54.815145 systemd[1]: Reached target integritysetup.target - Local Integrity Protected Volumes. Sep 4 01:15:54.815156 systemd[1]: Reached target remote-cryptsetup.target - Remote Encrypted Volumes. Sep 4 01:15:54.815168 systemd[1]: Reached target remote-fs.target - Remote File Systems. Sep 4 01:15:54.815180 systemd[1]: Reached target remote-veritysetup.target - Remote Verity Protected Volumes. Sep 4 01:15:54.815191 systemd[1]: Reached target slices.target - Slice Units. Sep 4 01:15:54.815203 systemd[1]: Reached target swap.target - Swaps. Sep 4 01:15:54.815215 systemd[1]: Reached target veritysetup.target - Local Verity Protected Volumes. Sep 4 01:15:54.815228 systemd[1]: Listening on systemd-coredump.socket - Process Core Dump Socket. Sep 4 01:15:54.815242 systemd[1]: Listening on systemd-creds.socket - Credential Encryption/Decryption. Sep 4 01:15:54.815253 systemd[1]: Listening on systemd-journald-audit.socket - Journal Audit Socket. Sep 4 01:15:54.815264 systemd[1]: Listening on systemd-mountfsd.socket - DDI File System Mounter Socket. Sep 4 01:15:54.815276 systemd[1]: Listening on systemd-networkd.socket - Network Service Netlink Socket. Sep 4 01:15:54.815287 systemd[1]: Listening on systemd-nsresourced.socket - Namespace Resource Manager Socket. Sep 4 01:15:54.815300 systemd[1]: Listening on systemd-oomd.socket - Userspace Out-Of-Memory (OOM) Killer Socket. Sep 4 01:15:54.815311 systemd[1]: Listening on systemd-udevd-control.socket - udev Control Socket. Sep 4 01:15:54.815322 systemd[1]: Listening on systemd-udevd-kernel.socket - udev Kernel Socket. Sep 4 01:15:54.815332 systemd[1]: Listening on systemd-userdbd.socket - User Database Manager Socket. Sep 4 01:15:54.815344 systemd[1]: Mounting dev-hugepages.mount - Huge Pages File System... Sep 4 01:15:54.815355 systemd[1]: Mounting dev-mqueue.mount - POSIX Message Queue File System... Sep 4 01:15:54.815365 systemd[1]: Mounting media.mount - External Media Directory... Sep 4 01:15:54.815378 systemd[1]: proc-xen.mount - /proc/xen was skipped because of an unmet condition check (ConditionVirtualization=xen). Sep 4 01:15:54.815390 systemd[1]: Mounting sys-kernel-debug.mount - Kernel Debug File System... Sep 4 01:15:54.815401 systemd[1]: Mounting sys-kernel-tracing.mount - Kernel Trace File System... Sep 4 01:15:54.815412 systemd[1]: Mounting tmp.mount - Temporary Directory /tmp... Sep 4 01:15:54.815424 systemd[1]: var-lib-machines.mount - Virtual Machine and Container Storage (Compatibility) was skipped because of an unmet condition check (ConditionPathExists=/var/lib/machines.raw). Sep 4 01:15:54.815435 systemd[1]: Reached target machines.target - Containers. Sep 4 01:15:54.815445 systemd[1]: Starting flatcar-tmpfiles.service - Create missing system files... Sep 4 01:15:54.815458 systemd[1]: ignition-delete-config.service - Ignition (delete config) was skipped because no trigger condition checks were met. Sep 4 01:15:54.815471 systemd[1]: Starting kmod-static-nodes.service - Create List of Static Device Nodes... Sep 4 01:15:54.815482 systemd[1]: Starting modprobe@configfs.service - Load Kernel Module configfs... Sep 4 01:15:54.815493 systemd[1]: Starting modprobe@dm_mod.service - Load Kernel Module dm_mod... Sep 4 01:15:54.815504 systemd[1]: Starting modprobe@drm.service - Load Kernel Module drm... Sep 4 01:15:54.815515 systemd[1]: Starting modprobe@efi_pstore.service - Load Kernel Module efi_pstore... Sep 4 01:15:54.815528 systemd[1]: Starting modprobe@fuse.service - Load Kernel Module fuse... Sep 4 01:15:54.815540 systemd[1]: Starting modprobe@loop.service - Load Kernel Module loop... Sep 4 01:15:54.815552 systemd[1]: setup-nsswitch.service - Create /etc/nsswitch.conf was skipped because of an unmet condition check (ConditionPathExists=!/etc/nsswitch.conf). Sep 4 01:15:54.815564 systemd[1]: systemd-fsck-root.service: Deactivated successfully. Sep 4 01:15:54.815575 systemd[1]: Stopped systemd-fsck-root.service - File System Check on Root Device. Sep 4 01:15:54.815587 systemd[1]: systemd-fsck-usr.service: Deactivated successfully. Sep 4 01:15:54.815598 systemd[1]: Stopped systemd-fsck-usr.service. Sep 4 01:15:54.815611 systemd[1]: systemd-hibernate-clear.service - Clear Stale Hibernate Storage Info was skipped because of an unmet condition check (ConditionPathExists=/sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67). Sep 4 01:15:54.815623 systemd[1]: Starting systemd-journald.service - Journal Service... Sep 4 01:15:54.815635 systemd[1]: Starting systemd-modules-load.service - Load Kernel Modules... Sep 4 01:15:54.815646 systemd[1]: Starting systemd-network-generator.service - Generate network units from Kernel command line... Sep 4 01:15:54.815657 kernel: fuse: init (API version 7.41) Sep 4 01:15:54.815668 systemd[1]: Starting systemd-remount-fs.service - Remount Root and Kernel File Systems... Sep 4 01:15:54.815704 systemd-journald[2064]: Collecting audit messages is enabled. Sep 4 01:15:54.815733 systemd[1]: Starting systemd-udev-load-credentials.service - Load udev Rules from Credentials... Sep 4 01:15:54.815746 systemd-journald[2064]: Journal started Sep 4 01:15:54.815777 systemd-journald[2064]: Runtime Journal (/run/log/journal/4c9f831b92254b8988027bb868ba9df3) is 8M, max 158.5M, 150.5M free. Sep 4 01:15:54.486000 audit[1]: EVENT_LISTENER pid=1 uid=0 auid=4294967295 tty=(none) ses=4294967295 subj=system_u:system_r:kernel_t:s0 comm="systemd" exe="/usr/lib/systemd/systemd" nl-mcgrp=1 op=connect res=1 Sep 4 01:15:54.729000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-fsck-root comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.734000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-fsck-usr comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.737000 audit: BPF prog-id=14 op=UNLOAD Sep 4 01:15:54.737000 audit: BPF prog-id=13 op=UNLOAD Sep 4 01:15:54.737000 audit: BPF prog-id=15 op=LOAD Sep 4 01:15:54.737000 audit: BPF prog-id=16 op=LOAD Sep 4 01:15:54.737000 audit: BPF prog-id=17 op=LOAD Sep 4 01:15:54.809000 audit: CONFIG_CHANGE op=set audit_enabled=1 old=1 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 res=1 Sep 4 01:15:54.809000 audit[2064]: SYSCALL arch=c000003e syscall=46 success=yes exit=60 a0=6 a1=7ffed03ceee0 a2=4000 a3=0 items=0 ppid=1 pid=2064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-journal" exe="/usr/lib/systemd/systemd-journald" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:15:54.809000 audit: PROCTITLE proctitle="/usr/lib/systemd/systemd-journald" Sep 4 01:15:54.335521 systemd[1]: Queued start job for default target multi-user.target. Sep 4 01:15:54.346532 systemd[1]: Unnecessary job was removed for dev-nvme0n1p6.device - /dev/nvme0n1p6. Sep 4 01:15:54.349254 systemd[1]: systemd-journald.service: Deactivated successfully. Sep 4 01:15:54.823713 systemd[1]: Starting systemd-udev-trigger.service - Coldplug All udev Devices... Sep 4 01:15:54.829859 systemd[1]: xenserver-pv-version.service - Set fake PV driver version for XenServer was skipped because of an unmet condition check (ConditionVirtualization=xen). Sep 4 01:15:54.832862 systemd[1]: Started systemd-journald.service - Journal Service. Sep 4 01:15:54.832000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-journald comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.834210 systemd[1]: Mounted dev-hugepages.mount - Huge Pages File System. Sep 4 01:15:54.835527 systemd[1]: Mounted dev-mqueue.mount - POSIX Message Queue File System. Sep 4 01:15:54.837986 systemd[1]: Mounted media.mount - External Media Directory. Sep 4 01:15:54.839296 systemd[1]: Mounted sys-kernel-debug.mount - Kernel Debug File System. Sep 4 01:15:54.842107 systemd[1]: Mounted sys-kernel-tracing.mount - Kernel Trace File System. Sep 4 01:15:54.846070 systemd[1]: Mounted tmp.mount - Temporary Directory /tmp. Sep 4 01:15:54.847785 systemd[1]: Finished kmod-static-nodes.service - Create List of Static Device Nodes. Sep 4 01:15:54.849000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kmod-static-nodes comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.850175 systemd[1]: modprobe@configfs.service: Deactivated successfully. Sep 4 01:15:54.850337 systemd[1]: Finished modprobe@configfs.service - Load Kernel Module configfs. Sep 4 01:15:54.851000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@configfs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.851000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@configfs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.852650 systemd[1]: modprobe@dm_mod.service: Deactivated successfully. Sep 4 01:15:54.853290 systemd[1]: Finished modprobe@dm_mod.service - Load Kernel Module dm_mod. Sep 4 01:15:54.853000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@dm_mod comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.853000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@dm_mod comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.855143 systemd[1]: modprobe@efi_pstore.service: Deactivated successfully. Sep 4 01:15:54.855287 systemd[1]: Finished modprobe@efi_pstore.service - Load Kernel Module efi_pstore. Sep 4 01:15:54.856000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@efi_pstore comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.856000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@efi_pstore comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.858180 systemd[1]: modprobe@fuse.service: Deactivated successfully. Sep 4 01:15:54.858356 systemd[1]: Finished modprobe@fuse.service - Load Kernel Module fuse. Sep 4 01:15:54.861080 systemd[1]: modprobe@loop.service: Deactivated successfully. Sep 4 01:15:54.861231 systemd[1]: Finished modprobe@loop.service - Load Kernel Module loop. Sep 4 01:15:54.859000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@fuse comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.859000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@fuse comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.862000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@loop comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.862000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@loop comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.864419 systemd[1]: Finished systemd-modules-load.service - Load Kernel Modules. Sep 4 01:15:54.864000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-modules-load comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.867133 systemd[1]: Finished systemd-network-generator.service - Generate network units from Kernel command line. Sep 4 01:15:54.868000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-network-generator comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.875654 systemd[1]: Finished systemd-remount-fs.service - Remount Root and Kernel File Systems. Sep 4 01:15:54.878000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-remount-fs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.883726 systemd[1]: Reached target network-pre.target - Preparation for Network. Sep 4 01:15:54.914385 systemd[1]: Listening on systemd-importd.socket - Disk Image Download Service Socket. Sep 4 01:15:54.931875 kernel: ACPI: bus type drm_connector registered Sep 4 01:15:54.920932 systemd[1]: Mounting sys-fs-fuse-connections.mount - FUSE Control File System... Sep 4 01:15:54.924929 systemd[1]: Mounting sys-kernel-config.mount - Kernel Configuration File System... Sep 4 01:15:54.926731 systemd[1]: remount-root.service - Remount Root File System was skipped because of an unmet condition check (ConditionPathIsReadWrite=!/). Sep 4 01:15:54.926761 systemd[1]: Reached target local-fs.target - Local File Systems. Sep 4 01:15:54.932855 systemd[1]: Listening on systemd-sysext.socket - System Extension Image Management. Sep 4 01:15:54.937652 systemd[1]: systemd-binfmt.service - Set Up Additional Binary Formats was skipped because no trigger condition checks were met. Sep 4 01:15:54.937761 systemd[1]: systemd-confext.service - Merge System Configuration Images into /etc/ was skipped because no trigger condition checks were met. Sep 4 01:15:54.941959 systemd[1]: Starting systemd-hwdb-update.service - Rebuild Hardware Database... Sep 4 01:15:54.944817 systemd[1]: Starting systemd-journal-flush.service - Flush Journal to Persistent Storage... Sep 4 01:15:54.946860 systemd[1]: systemd-pstore.service - Platform Persistent Storage Archival was skipped because of an unmet condition check (ConditionDirectoryNotEmpty=/sys/fs/pstore). Sep 4 01:15:54.949403 systemd[1]: Starting systemd-random-seed.service - Load/Save OS Random Seed... Sep 4 01:15:54.952148 systemd[1]: systemd-repart.service - Repartition Root Disk was skipped because no trigger condition checks were met. Sep 4 01:15:54.958886 systemd[1]: Starting systemd-sysctl.service - Apply Kernel Variables... Sep 4 01:15:54.963135 systemd[1]: Starting systemd-sysext.service - Merge System Extension Images into /usr/ and /opt/... Sep 4 01:15:54.967414 systemd[1]: modprobe@drm.service: Deactivated successfully. Sep 4 01:15:54.971027 systemd[1]: Finished modprobe@drm.service - Load Kernel Module drm. Sep 4 01:15:54.971000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@drm comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.971000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@drm comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.973429 systemd[1]: Finished systemd-udev-load-credentials.service - Load udev Rules from Credentials. Sep 4 01:15:54.973000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-udev-load-credentials comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.976540 systemd[1]: Mounted sys-fs-fuse-connections.mount - FUSE Control File System. Sep 4 01:15:54.979461 systemd[1]: Mounted sys-kernel-config.mount - Kernel Configuration File System. Sep 4 01:15:54.993742 systemd[1]: Finished systemd-udev-trigger.service - Coldplug All udev Devices. Sep 4 01:15:54.995000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-udev-trigger comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:54.998388 systemd-journald[2064]: Time spent on flushing to /var/log/journal/4c9f831b92254b8988027bb868ba9df3 is 24.473ms for 1105 entries. Sep 4 01:15:54.998388 systemd-journald[2064]: System Journal (/var/log/journal/4c9f831b92254b8988027bb868ba9df3) is 8M, max 2.2G, 2.2G free. Sep 4 01:15:55.094029 systemd-journald[2064]: Received client request to flush runtime journal. Sep 4 01:15:55.094095 kernel: loop1: detected capacity change from 0 to 50784 Sep 4 01:15:55.007000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-random-seed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.005685 systemd[1]: Finished systemd-random-seed.service - Load/Save OS Random Seed. Sep 4 01:15:55.092000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.009104 systemd[1]: Reached target first-boot-complete.target - First Boot Complete. Sep 4 01:15:55.014992 systemd[1]: Starting systemd-machine-id-commit.service - Save Transient machine-id to Disk... Sep 4 01:15:55.092236 systemd[1]: Finished systemd-sysctl.service - Apply Kernel Variables. Sep 4 01:15:55.094222 systemd[1]: Finished flatcar-tmpfiles.service - Create missing system files. Sep 4 01:15:55.093000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=flatcar-tmpfiles comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.096772 systemd[1]: Finished systemd-journal-flush.service - Flush Journal to Persistent Storage. Sep 4 01:15:55.098000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-journal-flush comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.101412 systemd[1]: Starting systemd-sysusers.service - Create System Users... Sep 4 01:15:55.226574 systemd[1]: Finished systemd-machine-id-commit.service - Save Transient machine-id to Disk. Sep 4 01:15:55.228000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-machine-id-commit comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.356264 systemd[1]: etc-machine\x2did.mount: Deactivated successfully. Sep 4 01:15:55.446297 systemd[1]: Finished systemd-sysusers.service - Create System Users. Sep 4 01:15:55.447000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-sysusers comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.449000 audit: BPF prog-id=18 op=LOAD Sep 4 01:15:55.449000 audit: BPF prog-id=19 op=LOAD Sep 4 01:15:55.449000 audit: BPF prog-id=20 op=LOAD Sep 4 01:15:55.453074 systemd[1]: Starting systemd-oomd.service - Userspace Out-Of-Memory (OOM) Killer... Sep 4 01:15:55.454000 audit: BPF prog-id=21 op=LOAD Sep 4 01:15:55.456129 systemd[1]: Starting systemd-resolved.service - Network Name Resolution... Sep 4 01:15:55.460808 systemd[1]: Starting systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev... Sep 4 01:15:55.469000 audit: BPF prog-id=22 op=LOAD Sep 4 01:15:55.469000 audit: BPF prog-id=23 op=LOAD Sep 4 01:15:55.469000 audit: BPF prog-id=24 op=LOAD Sep 4 01:15:55.473980 systemd[1]: Starting systemd-nsresourced.service - Namespace Resource Manager... Sep 4 01:15:55.477000 audit: BPF prog-id=25 op=LOAD Sep 4 01:15:55.477000 audit: BPF prog-id=26 op=LOAD Sep 4 01:15:55.477000 audit: BPF prog-id=27 op=LOAD Sep 4 01:15:55.480712 systemd[1]: Starting systemd-userdbd.service - User Database Manager... Sep 4 01:15:55.537858 kernel: loop2: detected capacity change from 0 to 25512 Sep 4 01:15:55.543732 systemd-nsresourced[2144]: Not setting up BPF subsystem, as functionality has been disabled at compile time. Sep 4 01:15:55.544000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-nsresourced comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.544724 systemd[1]: Started systemd-nsresourced.service - Namespace Resource Manager. Sep 4 01:15:55.555719 systemd[1]: Started systemd-userdbd.service - User Database Manager. Sep 4 01:15:55.557000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-userdbd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.638446 systemd-tmpfiles[2143]: ACLs are not supported, ignoring. Sep 4 01:15:55.638809 systemd-tmpfiles[2143]: ACLs are not supported, ignoring. Sep 4 01:15:55.642778 systemd[1]: Finished systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev. Sep 4 01:15:55.643000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-tmpfiles-setup-dev comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.645946 systemd-oomd[2141]: No swap; memory pressure usage will be degraded Sep 4 01:15:55.651000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-oomd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.647324 systemd[1]: Started systemd-oomd.service - Userspace Out-Of-Memory (OOM) Killer. Sep 4 01:15:55.658266 systemd-resolved[2142]: Positive Trust Anchors: Sep 4 01:15:55.658502 systemd-resolved[2142]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d Sep 4 01:15:55.658508 systemd-resolved[2142]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 Sep 4 01:15:55.658543 systemd-resolved[2142]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test Sep 4 01:15:55.714421 systemd[1]: Finished systemd-hwdb-update.service - Rebuild Hardware Database. Sep 4 01:15:55.715000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-hwdb-update comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.715000 audit: BPF prog-id=8 op=UNLOAD Sep 4 01:15:55.715000 audit: BPF prog-id=7 op=UNLOAD Sep 4 01:15:55.715000 audit: BPF prog-id=28 op=LOAD Sep 4 01:15:55.715000 audit: BPF prog-id=29 op=LOAD Sep 4 01:15:55.718263 systemd[1]: Starting systemd-udevd.service - Rule-based Manager for Device Events and Files... Sep 4 01:15:55.748036 systemd-udevd[2165]: Using default interface naming scheme 'v257'. Sep 4 01:15:55.828983 systemd-resolved[2142]: Using system hostname 'ci-4593.2.5-n-471707002a'. Sep 4 01:15:55.830191 systemd[1]: Started systemd-resolved.service - Network Name Resolution. Sep 4 01:15:55.830000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-resolved comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.832753 systemd[1]: Reached target nss-lookup.target - Host and Network Name Lookups. Sep 4 01:15:55.962082 systemd[1]: Started systemd-udevd.service - Rule-based Manager for Device Events and Files. Sep 4 01:15:55.962000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-udevd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:55.965000 audit: BPF prog-id=30 op=LOAD Sep 4 01:15:55.968739 systemd[1]: Starting systemd-networkd.service - Network Configuration... Sep 4 01:15:56.009855 kernel: loop3: detected capacity change from 0 to 111560 Sep 4 01:15:56.018678 systemd[1]: Condition check resulted in dev-ttyS0.device - /dev/ttyS0 being skipped. Sep 4 01:15:56.080869 kernel: hv_vmbus: registering driver hyperv_fb Sep 4 01:15:56.083951 kernel: hyperv_fb: Synthvid Version major 3, minor 5 Sep 4 01:15:56.084006 kernel: hyperv_fb: Screen resolution: 1024x768, Color depth: 32, Frame buffer size: 8388608 Sep 4 01:15:56.088724 kernel: hv_vmbus: registering driver hv_balloon Sep 4 01:15:56.088796 kernel: Console: switching to colour dummy device 80x25 Sep 4 01:15:56.093875 kernel: hv_balloon: Using Dynamic Memory protocol version 2.0 Sep 4 01:15:56.093939 kernel: Console: switching to colour frame buffer device 128x48 Sep 4 01:15:56.093961 kernel: hv_storvsc f8b3781a-1e82-4818-a1c3-63d806ec15bb: tag#241 cmd 0x85 status: scsi 0x2 srb 0x6 hv 0xc0000001 Sep 4 01:15:56.104967 systemd-networkd[2174]: lo: Link UP Sep 4 01:15:56.104976 systemd-networkd[2174]: lo: Gained carrier Sep 4 01:15:56.106320 systemd[1]: Started systemd-networkd.service - Network Configuration. Sep 4 01:15:56.106000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-networkd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.108807 systemd[1]: Reached target network.target - Network. Sep 4 01:15:56.111245 systemd-networkd[2174]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Sep 4 01:15:56.111869 systemd-networkd[2174]: eth0: Configuring with /usr/lib/systemd/network/zz-default.network. Sep 4 01:15:56.114760 kernel: mana 7870:00:00.0 enP30832s1: Configured vPort 0 PD 18 DB 16 Sep 4 01:15:56.115410 systemd[1]: Starting systemd-networkd-persistent-storage.service - Enable Persistent Storage in systemd-networkd... Sep 4 01:15:56.118972 systemd[1]: Starting systemd-networkd-wait-online.service - Wait for Network to be Configured... Sep 4 01:15:56.124871 kernel: mana 7870:00:00.0 enP30832s1: Configured steering vPort 0 entries 64 Sep 4 01:15:56.126860 kernel: hv_netvsc f8615163-0000-1000-2000-70a8a57fdb30 eth0: Data path switched to VF: enP30832s1 Sep 4 01:15:56.129416 systemd-networkd[2174]: enP30832s1: Link UP Sep 4 01:15:56.129511 systemd-networkd[2174]: eth0: Link UP Sep 4 01:15:56.129514 systemd-networkd[2174]: eth0: Gained carrier Sep 4 01:15:56.129528 systemd-networkd[2174]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Sep 4 01:15:56.135180 systemd-networkd[2174]: enP30832s1: Gained carrier Sep 4 01:15:56.146924 systemd-networkd[2174]: eth0: DHCPv4 address 10.0.0.35/24, gateway 10.0.0.1 acquired from 168.63.129.16 Sep 4 01:15:56.158144 kernel: mousedev: PS/2 mouse device common for all mice Sep 4 01:15:56.204918 systemd[1]: Finished systemd-networkd-persistent-storage.service - Enable Persistent Storage in systemd-networkd. Sep 4 01:15:56.207000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-networkd-persistent-storage comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.253171 systemd[1]: Starting systemd-vconsole-setup.service - Virtual Console Setup... Sep 4 01:15:56.265307 systemd[1]: systemd-vconsole-setup.service: Deactivated successfully. Sep 4 01:15:56.265503 systemd[1]: Stopped systemd-vconsole-setup.service - Virtual Console Setup. Sep 4 01:15:56.265000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.265000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.269949 systemd[1]: Starting systemd-vconsole-setup.service - Virtual Console Setup... Sep 4 01:15:56.299799 systemd[1]: systemd-vconsole-setup.service: Deactivated successfully. Sep 4 01:15:56.300543 systemd[1]: Stopped systemd-vconsole-setup.service - Virtual Console Setup. Sep 4 01:15:56.300000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.301000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.306962 systemd[1]: Starting systemd-vconsole-setup.service - Virtual Console Setup... Sep 4 01:15:56.387626 systemd[1]: Found device dev-disk-by\x2dlabel-OEM.device - MSFT NVMe Accelerator v1.0 OEM. Sep 4 01:15:56.399961 kernel: kvm_intel: Using Hyper-V Enlightened VMCS Sep 4 01:15:56.400043 kernel: cpu_based_exec_ctrl unsupported with eVMCS: 0x20000 Sep 4 01:15:56.401007 systemd[1]: Starting systemd-fsck@dev-disk-by\x2dlabel-OEM.service - File System Check on /dev/disk/by-label/OEM... Sep 4 01:15:56.408883 kernel: loop4: detected capacity change from 0 to 50784 Sep 4 01:15:56.425858 kernel: loop5: detected capacity change from 0 to 25512 Sep 4 01:15:56.437210 kernel: loop6: detected capacity change from 0 to 111560 Sep 4 01:15:56.447598 (sd-merge)[2251]: Using extensions 'containerd-flatcar.raw', 'docker-flatcar.raw', 'oem-azure.raw'. Sep 4 01:15:56.450421 (sd-merge)[2251]: Merged extensions into '/usr'. Sep 4 01:15:56.454324 systemd[1]: Finished systemd-sysext.service - Merge System Extension Images into /usr/ and /opt/. Sep 4 01:15:56.452000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-sysext comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.456699 systemd[1]: Starting ensure-sysext.service... Sep 4 01:15:56.460961 systemd[1]: Starting systemd-tmpfiles-setup.service - Create System Files and Directories... Sep 4 01:15:56.481004 systemd[1]: Finished systemd-fsck@dev-disk-by\x2dlabel-OEM.service - File System Check on /dev/disk/by-label/OEM. Sep 4 01:15:56.479000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-fsck@dev-disk-by\x2dlabel-OEM comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.484465 systemd[1]: Reload requested from client PID 2254 ('systemctl') (unit ensure-sysext.service)... Sep 4 01:15:56.484480 systemd[1]: Reloading... Sep 4 01:15:56.508657 systemd-tmpfiles[2255]: /usr/lib/tmpfiles.d/nfs-utils.conf:6: Duplicate line for path "/var/lib/nfs/sm", ignoring. Sep 4 01:15:56.508684 systemd-tmpfiles[2255]: /usr/lib/tmpfiles.d/nfs-utils.conf:7: Duplicate line for path "/var/lib/nfs/sm.bak", ignoring. Sep 4 01:15:56.508880 systemd-tmpfiles[2255]: /usr/lib/tmpfiles.d/provision.conf:20: Duplicate line for path "/root", ignoring. Sep 4 01:15:56.509624 systemd-tmpfiles[2255]: ACLs are not supported, ignoring. Sep 4 01:15:56.509680 systemd-tmpfiles[2255]: ACLs are not supported, ignoring. Sep 4 01:15:56.528079 systemd-tmpfiles[2255]: Detected autofs mount point /boot during canonicalization of boot. Sep 4 01:15:56.528089 systemd-tmpfiles[2255]: Skipping /boot Sep 4 01:15:56.554055 systemd-tmpfiles[2255]: Detected autofs mount point /boot during canonicalization of boot. Sep 4 01:15:56.554068 systemd-tmpfiles[2255]: Skipping /boot Sep 4 01:15:56.568879 zram_generator::config[2299]: No configuration found. Sep 4 01:15:56.731029 systemd[1]: Reloading finished in 246 ms. Sep 4 01:15:56.750000 audit: BPF prog-id=31 op=LOAD Sep 4 01:15:56.750000 audit: BPF prog-id=22 op=UNLOAD Sep 4 01:15:56.750000 audit: BPF prog-id=32 op=LOAD Sep 4 01:15:56.750000 audit: BPF prog-id=33 op=LOAD Sep 4 01:15:56.750000 audit: BPF prog-id=23 op=UNLOAD Sep 4 01:15:56.750000 audit: BPF prog-id=24 op=UNLOAD Sep 4 01:15:56.751000 audit: BPF prog-id=34 op=LOAD Sep 4 01:15:56.751000 audit: BPF prog-id=25 op=UNLOAD Sep 4 01:15:56.751000 audit: BPF prog-id=35 op=LOAD Sep 4 01:15:56.751000 audit: BPF prog-id=36 op=LOAD Sep 4 01:15:56.751000 audit: BPF prog-id=26 op=UNLOAD Sep 4 01:15:56.751000 audit: BPF prog-id=27 op=UNLOAD Sep 4 01:15:56.751000 audit: BPF prog-id=37 op=LOAD Sep 4 01:15:56.751000 audit: BPF prog-id=38 op=LOAD Sep 4 01:15:56.751000 audit: BPF prog-id=28 op=UNLOAD Sep 4 01:15:56.751000 audit: BPF prog-id=29 op=UNLOAD Sep 4 01:15:56.752000 audit: BPF prog-id=39 op=LOAD Sep 4 01:15:56.752000 audit: BPF prog-id=30 op=UNLOAD Sep 4 01:15:56.753000 audit: BPF prog-id=40 op=LOAD Sep 4 01:15:56.753000 audit: BPF prog-id=21 op=UNLOAD Sep 4 01:15:56.754000 audit: BPF prog-id=41 op=LOAD Sep 4 01:15:56.754000 audit: BPF prog-id=18 op=UNLOAD Sep 4 01:15:56.754000 audit: BPF prog-id=42 op=LOAD Sep 4 01:15:56.757000 audit: BPF prog-id=43 op=LOAD Sep 4 01:15:56.757000 audit: BPF prog-id=19 op=UNLOAD Sep 4 01:15:56.757000 audit: BPF prog-id=20 op=UNLOAD Sep 4 01:15:56.757000 audit: BPF prog-id=44 op=LOAD Sep 4 01:15:56.757000 audit: BPF prog-id=15 op=UNLOAD Sep 4 01:15:56.757000 audit: BPF prog-id=45 op=LOAD Sep 4 01:15:56.757000 audit: BPF prog-id=46 op=LOAD Sep 4 01:15:56.757000 audit: BPF prog-id=16 op=UNLOAD Sep 4 01:15:56.757000 audit: BPF prog-id=17 op=UNLOAD Sep 4 01:15:56.761345 systemd[1]: Finished systemd-tmpfiles-setup.service - Create System Files and Directories. Sep 4 01:15:56.759000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-tmpfiles-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.770346 systemd[1]: Starting audit-rules.service - Load Audit Rules... Sep 4 01:15:56.774028 systemd[1]: Starting clean-ca-certificates.service - Clean up broken links in /etc/ssl/certs... Sep 4 01:15:56.778946 systemd[1]: Starting ldconfig.service - Rebuild Dynamic Linker Cache... Sep 4 01:15:56.782046 systemd[1]: Starting systemd-journal-catalog-update.service - Rebuild Journal Catalog... Sep 4 01:15:56.787610 systemd[1]: Starting systemd-update-utmp.service - Record System Boot/Shutdown in UTMP... Sep 4 01:15:56.793559 systemd[1]: proc-xen.mount - /proc/xen was skipped because of an unmet condition check (ConditionVirtualization=xen). Sep 4 01:15:56.793698 systemd[1]: ignition-delete-config.service - Ignition (delete config) was skipped because no trigger condition checks were met. Sep 4 01:15:56.796068 systemd[1]: Starting modprobe@dm_mod.service - Load Kernel Module dm_mod... Sep 4 01:15:56.798945 systemd[1]: Starting modprobe@efi_pstore.service - Load Kernel Module efi_pstore... Sep 4 01:15:56.802166 systemd[1]: Starting modprobe@loop.service - Load Kernel Module loop... Sep 4 01:15:56.804954 systemd[1]: systemd-binfmt.service - Set Up Additional Binary Formats was skipped because no trigger condition checks were met. Sep 4 01:15:56.805140 systemd[1]: systemd-confext.service - Merge System Configuration Images into /etc/ was skipped because no trigger condition checks were met. Sep 4 01:15:56.805241 systemd[1]: systemd-hibernate-clear.service - Clear Stale Hibernate Storage Info was skipped because of an unmet condition check (ConditionPathExists=/sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67). Sep 4 01:15:56.805326 systemd[1]: xenserver-pv-version.service - Set fake PV driver version for XenServer was skipped because of an unmet condition check (ConditionVirtualization=xen). Sep 4 01:15:56.809724 systemd[1]: proc-xen.mount - /proc/xen was skipped because of an unmet condition check (ConditionVirtualization=xen). Sep 4 01:15:56.810183 systemd[1]: ignition-delete-config.service - Ignition (delete config) was skipped because no trigger condition checks were met. Sep 4 01:15:56.810384 systemd[1]: systemd-binfmt.service - Set Up Additional Binary Formats was skipped because no trigger condition checks were met. Sep 4 01:15:56.810618 systemd[1]: systemd-confext.service - Merge System Configuration Images into /etc/ was skipped because no trigger condition checks were met. Sep 4 01:15:56.811027 systemd[1]: systemd-hibernate-clear.service - Clear Stale Hibernate Storage Info was skipped because of an unmet condition check (ConditionPathExists=/sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67). Sep 4 01:15:56.811116 systemd[1]: xenserver-pv-version.service - Set fake PV driver version for XenServer was skipped because of an unmet condition check (ConditionVirtualization=xen). Sep 4 01:15:56.819000 audit[2355]: SYSTEM_BOOT pid=2355 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg=' comm="systemd-update-utmp" exe="/usr/lib/systemd/systemd-update-utmp" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.822811 systemd[1]: Finished systemd-vconsole-setup.service - Virtual Console Setup. Sep 4 01:15:56.824000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-vconsole-setup comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.828723 systemd[1]: modprobe@dm_mod.service: Deactivated successfully. Sep 4 01:15:56.829033 systemd[1]: Finished modprobe@dm_mod.service - Load Kernel Module dm_mod. Sep 4 01:15:56.828000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@dm_mod comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.828000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@dm_mod comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.830708 systemd[1]: modprobe@efi_pstore.service: Deactivated successfully. Sep 4 01:15:56.830901 systemd[1]: Finished modprobe@efi_pstore.service - Load Kernel Module efi_pstore. Sep 4 01:15:56.831000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@efi_pstore comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.831000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@efi_pstore comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.832973 systemd[1]: modprobe@loop.service: Deactivated successfully. Sep 4 01:15:56.833157 systemd[1]: Finished modprobe@loop.service - Load Kernel Module loop. Sep 4 01:15:56.834000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@loop comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.834000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@loop comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.840979 systemd[1]: Finished ensure-sysext.service. Sep 4 01:15:56.842000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=ensure-sysext comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.844166 systemd[1]: Finished systemd-update-utmp.service - Record System Boot/Shutdown in UTMP. Sep 4 01:15:56.845000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-update-utmp comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.848818 systemd[1]: proc-xen.mount - /proc/xen was skipped because of an unmet condition check (ConditionVirtualization=xen). Sep 4 01:15:56.849058 systemd[1]: ignition-delete-config.service - Ignition (delete config) was skipped because no trigger condition checks were met. Sep 4 01:15:56.849874 systemd[1]: Starting modprobe@drm.service - Load Kernel Module drm... Sep 4 01:15:56.851423 systemd[1]: systemd-binfmt.service - Set Up Additional Binary Formats was skipped because no trigger condition checks were met. Sep 4 01:15:56.851489 systemd[1]: systemd-confext.service - Merge System Configuration Images into /etc/ was skipped because no trigger condition checks were met. Sep 4 01:15:56.851516 systemd[1]: systemd-hibernate-clear.service - Clear Stale Hibernate Storage Info was skipped because of an unmet condition check (ConditionPathExists=/sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67). Sep 4 01:15:56.851545 systemd[1]: systemd-pstore.service - Platform Persistent Storage Archival was skipped because of an unmet condition check (ConditionDirectoryNotEmpty=/sys/fs/pstore). Sep 4 01:15:56.851575 systemd[1]: systemd-repart.service - Repartition Root Disk was skipped because no trigger condition checks were met. Sep 4 01:15:56.851597 systemd[1]: Reached target time-set.target - System Time Set. Sep 4 01:15:56.853418 systemd[1]: xenserver-pv-version.service - Set fake PV driver version for XenServer was skipped because of an unmet condition check (ConditionVirtualization=xen). Sep 4 01:15:56.867153 systemd[1]: modprobe@drm.service: Deactivated successfully. Sep 4 01:15:56.867460 systemd[1]: Finished modprobe@drm.service - Load Kernel Module drm. Sep 4 01:15:56.867000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@drm comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.867000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@drm comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:56.897067 systemd[1]: Finished systemd-journal-catalog-update.service - Rebuild Journal Catalog. Sep 4 01:15:56.896000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-journal-catalog-update comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:57.209998 systemd-networkd[2174]: eth0: Gained IPv6LL Sep 4 01:15:57.211909 systemd[1]: Finished systemd-networkd-wait-online.service - Wait for Network to be Configured. Sep 4 01:15:57.213000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-networkd-wait-online comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:15:57.215597 systemd[1]: Reached target network-online.target - Network is Online. Sep 4 01:15:57.271000 audit: CONFIG_CHANGE auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 op=add_rule key=(null) list=5 res=1 Sep 4 01:15:57.271000 audit[2388]: SYSCALL arch=c000003e syscall=44 success=yes exit=1056 a0=3 a1=7ffd46d06ba0 a2=420 a3=0 items=0 ppid=2351 pid=2388 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditctl" exe="/usr/bin/auditctl" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:15:57.271000 audit: PROCTITLE proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573 Sep 4 01:15:57.273663 augenrules[2388]: No rules Sep 4 01:15:57.274610 systemd[1]: audit-rules.service: Deactivated successfully. Sep 4 01:15:57.274898 systemd[1]: Finished audit-rules.service - Load Audit Rules. Sep 4 01:15:57.400964 systemd[1]: Finished clean-ca-certificates.service - Clean up broken links in /etc/ssl/certs. Sep 4 01:15:57.402813 systemd[1]: update-ca-certificates.service - Update CA bundle at /etc/ssl/certs/ca-certificates.crt was skipped because of an unmet condition check (ConditionPathIsSymbolicLink=!/etc/ssl/certs/ca-certificates.crt). Sep 4 01:16:02.457025 ldconfig[2353]: /sbin/ldconfig: /usr/lib/ld.so.conf is not an ELF file - it has the wrong magic bytes at the start. Sep 4 01:16:02.467141 systemd[1]: Finished ldconfig.service - Rebuild Dynamic Linker Cache. Sep 4 01:16:02.469797 systemd[1]: Starting systemd-update-done.service - Update is Completed... Sep 4 01:16:02.485735 systemd[1]: Finished systemd-update-done.service - Update is Completed. Sep 4 01:16:02.489175 systemd[1]: Reached target sysinit.target - System Initialization. Sep 4 01:16:02.490415 systemd[1]: Started motdgen.path - Watch for update engine configuration changes. Sep 4 01:16:02.491646 systemd[1]: Started user-cloudinit@var-lib-flatcar\x2dinstall-user_data.path - Watch for a cloud-config at /var/lib/flatcar-install/user_data. Sep 4 01:16:02.494908 systemd[1]: Started google-oslogin-cache.timer - NSS cache refresh timer. Sep 4 01:16:02.496247 systemd[1]: Started logrotate.timer - Daily rotation of log files. Sep 4 01:16:02.498932 systemd[1]: Started mdadm.timer - Weekly check for MD array's redundancy information.. Sep 4 01:16:02.501897 systemd[1]: Started systemd-sysupdate-reboot.timer - Reboot Automatically After System Update. Sep 4 01:16:02.504924 systemd[1]: Started systemd-sysupdate.timer - Automatic System Update. Sep 4 01:16:02.506205 systemd[1]: Started systemd-tmpfiles-clean.timer - Daily Cleanup of Temporary Directories. Sep 4 01:16:02.508889 systemd[1]: update-engine-stub.timer - Update Engine Stub Timer was skipped because of an unmet condition check (ConditionPathExists=/usr/.noupdate). Sep 4 01:16:02.508922 systemd[1]: Reached target paths.target - Path Units. Sep 4 01:16:02.509724 systemd[1]: Reached target timers.target - Timer Units. Sep 4 01:16:02.512534 systemd[1]: Listening on dbus.socket - D-Bus System Message Bus Socket. Sep 4 01:16:02.514983 systemd[1]: Starting docker.socket - Docker Socket for the API... Sep 4 01:16:02.517615 systemd[1]: Listening on sshd-unix-local.socket - OpenSSH Server Socket (systemd-ssh-generator, AF_UNIX Local). Sep 4 01:16:02.519159 systemd[1]: Listening on sshd-vsock.socket - OpenSSH Server Socket (systemd-ssh-generator, AF_VSOCK). Sep 4 01:16:02.520725 systemd[1]: Reached target ssh-access.target - SSH Access Available. Sep 4 01:16:02.533431 systemd[1]: Listening on sshd.socket - OpenSSH Server Socket. Sep 4 01:16:02.536130 systemd[1]: Listening on systemd-hostnamed.socket - Hostname Service Socket. Sep 4 01:16:02.539427 systemd[1]: Listening on docker.socket - Docker Socket for the API. Sep 4 01:16:02.542555 systemd[1]: Reached target sockets.target - Socket Units. Sep 4 01:16:02.543645 systemd[1]: Reached target basic.target - Basic System. Sep 4 01:16:02.544596 systemd[1]: addon-config@oem.service - Configure Addon /oem was skipped because no trigger condition checks were met. Sep 4 01:16:02.544616 systemd[1]: addon-run@oem.service - Run Addon /oem was skipped because no trigger condition checks were met. Sep 4 01:16:02.546511 systemd[1]: Starting chronyd.service - NTP client/server... Sep 4 01:16:02.548694 systemd[1]: Starting containerd.service - containerd container runtime... Sep 4 01:16:02.556479 systemd[1]: Starting coreos-metadata.service - Flatcar Metadata Agent... Sep 4 01:16:02.560272 systemd[1]: Starting dbus.service - D-Bus System Message Bus... Sep 4 01:16:02.566961 systemd[1]: Starting dracut-shutdown.service - Restore /run/initramfs on shutdown... Sep 4 01:16:02.571030 systemd[1]: Starting enable-oem-cloudinit.service - Enable cloudinit... Sep 4 01:16:02.575032 systemd[1]: Starting extend-filesystems.service - Extend Filesystems... Sep 4 01:16:02.577135 systemd[1]: flatcar-setup-environment.service - Modifies /etc/environment for CoreOS was skipped because of an unmet condition check (ConditionPathExists=/oem/bin/flatcar-setup-environment). Sep 4 01:16:02.581804 systemd[1]: Starting google-oslogin-cache.service - NSS cache refresh... Sep 4 01:16:02.583732 systemd[1]: hv_fcopy_uio_daemon.service - Hyper-V FCOPY UIO daemon was skipped because of an unmet condition check (ConditionPathExists=/sys/bus/vmbus/devices/eb765408-105f-49b6-b4aa-c123b64d17d4/uio). Sep 4 01:16:02.586077 systemd[1]: Started hv_kvp_daemon.service - Hyper-V KVP daemon. Sep 4 01:16:02.587755 systemd[1]: hv_vss_daemon.service - Hyper-V VSS daemon was skipped because of an unmet condition check (ConditionPathExists=/dev/vmbus/hv_vss). Sep 4 01:16:02.591416 systemd[1]: Starting motdgen.service - Generate /run/flatcar/motd... Sep 4 01:16:02.597153 systemd[1]: Starting nvidia.service - NVIDIA Configure Service... Sep 4 01:16:02.601036 systemd[1]: Starting ssh-key-proc-cmdline.service - Install an ssh key from /proc/cmdline... Sep 4 01:16:02.604300 KVP[2411]: KVP starting; pid is:2411 Sep 4 01:16:02.608007 systemd[1]: Starting sshd-keygen.service - Generate sshd host keys... Sep 4 01:16:02.614389 systemd[1]: Starting systemd-logind.service - User Login Management... Sep 4 01:16:02.616964 systemd[1]: tcsd.service - TCG Core Services Daemon was skipped because of an unmet condition check (ConditionPathExists=/dev/tpm0). Sep 4 01:16:02.618709 systemd[1]: cgroup compatibility translation between legacy and unified hierarchy settings activated. See cgroup-compat debug messages for details. Sep 4 01:16:02.621955 kernel: hv_utils: KVP IC version 4.0 Sep 4 01:16:02.619959 KVP[2411]: KVP LIC Version: 3.1 Sep 4 01:16:02.622083 systemd[1]: Starting update-engine.service - Update Engine... Sep 4 01:16:02.626002 systemd[1]: Starting update-ssh-keys-after-ignition.service - Run update-ssh-keys once after Ignition... Sep 4 01:16:02.631495 jq[2408]: false Sep 4 01:16:02.639109 systemd[1]: Finished dracut-shutdown.service - Restore /run/initramfs on shutdown. Sep 4 01:16:02.644540 systemd[1]: enable-oem-cloudinit.service: Skipped due to 'exec-condition'. Sep 4 01:16:02.644763 systemd[1]: Condition check resulted in enable-oem-cloudinit.service - Enable cloudinit being skipped. Sep 4 01:16:02.645006 systemd[1]: ssh-key-proc-cmdline.service: Deactivated successfully. Sep 4 01:16:02.645192 systemd[1]: Finished ssh-key-proc-cmdline.service - Install an ssh key from /proc/cmdline. Sep 4 01:16:02.648962 jq[2421]: true Sep 4 01:16:02.662632 google_oslogin_nss_cache[2410]: oslogin_cache_refresh[2410]: Refreshing passwd entry cache Sep 4 01:16:02.661694 oslogin_cache_refresh[2410]: Refreshing passwd entry cache Sep 4 01:16:02.674901 jq[2426]: true Sep 4 01:16:02.680281 extend-filesystems[2409]: Found /dev/nvme0n1p6 Sep 4 01:16:02.680172 systemd[1]: motdgen.service: Deactivated successfully. Sep 4 01:16:02.685296 google_oslogin_nss_cache[2410]: oslogin_cache_refresh[2410]: Failure getting users, quitting Sep 4 01:16:02.685296 google_oslogin_nss_cache[2410]: oslogin_cache_refresh[2410]: Produced empty passwd cache file, removing /etc/oslogin_passwd.cache.bak. Sep 4 01:16:02.685296 google_oslogin_nss_cache[2410]: oslogin_cache_refresh[2410]: Refreshing group entry cache Sep 4 01:16:02.679261 oslogin_cache_refresh[2410]: Failure getting users, quitting Sep 4 01:16:02.681537 systemd[1]: Finished motdgen.service - Generate /run/flatcar/motd. Sep 4 01:16:02.679276 oslogin_cache_refresh[2410]: Produced empty passwd cache file, removing /etc/oslogin_passwd.cache.bak. Sep 4 01:16:02.679315 oslogin_cache_refresh[2410]: Refreshing group entry cache Sep 4 01:16:02.684028 chronyd[2400]: chronyd version 4.8 starting (+CMDMON +REFCLOCK +RTC +PRIVDROP +SCFILTER -SIGND +NTS +SECHASH +IPV6 -DEBUG) Sep 4 01:16:02.687097 chronyd[2400]: Timezone right/UTC failed leap second check, ignoring Sep 4 01:16:02.687813 systemd[1]: Started chronyd.service - NTP client/server. Sep 4 01:16:02.687258 chronyd[2400]: Loaded seccomp filter (level 2) Sep 4 01:16:02.694918 google_oslogin_nss_cache[2410]: oslogin_cache_refresh[2410]: Failure getting groups, quitting Sep 4 01:16:02.694918 google_oslogin_nss_cache[2410]: oslogin_cache_refresh[2410]: Produced empty group cache file, removing /etc/oslogin_group.cache.bak. Sep 4 01:16:02.694734 oslogin_cache_refresh[2410]: Failure getting groups, quitting Sep 4 01:16:02.694744 oslogin_cache_refresh[2410]: Produced empty group cache file, removing /etc/oslogin_group.cache.bak. Sep 4 01:16:02.697427 systemd[1]: google-oslogin-cache.service: Deactivated successfully. Sep 4 01:16:02.697689 systemd[1]: Finished google-oslogin-cache.service - NSS cache refresh. Sep 4 01:16:02.704872 extend-filesystems[2409]: Found /dev/nvme0n1p9 Sep 4 01:16:02.713078 systemd[1]: Finished nvidia.service - NVIDIA Configure Service. Sep 4 01:16:02.715798 extend-filesystems[2409]: Checking size of /dev/nvme0n1p9 Sep 4 01:16:02.721872 update_engine[2419]: I20260904 01:16:02.721144 2419 main.cc:92] Flatcar Update Engine starting Sep 4 01:16:02.743866 extend-filesystems[2409]: Resized partition /dev/nvme0n1p9 Sep 4 01:16:02.760875 extend-filesystems[2477]: resize2fs 1.47.3 (8-Jul-2025) Sep 4 01:16:02.774933 kernel: EXT4-fs (nvme0n1p9): resizing filesystem from 6359552 to 6376955 blocks Sep 4 01:16:02.779166 kernel: EXT4-fs (nvme0n1p9): resized filesystem to 6376955 Sep 4 01:16:02.782511 systemd-logind[2416]: New seat seat0. Sep 4 01:16:02.810163 systemd-logind[2416]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Sep 4 01:16:02.810591 systemd[1]: Started systemd-logind.service - User Login Management. Sep 4 01:16:02.823528 extend-filesystems[2477]: Filesystem at /dev/nvme0n1p9 is mounted on /; on-line resizing required Sep 4 01:16:02.823528 extend-filesystems[2477]: old_desc_blocks = 4, new_desc_blocks = 4 Sep 4 01:16:02.823528 extend-filesystems[2477]: The filesystem on /dev/nvme0n1p9 is now 6376955 (4k) blocks long. Sep 4 01:16:02.822493 systemd[1]: extend-filesystems.service: Deactivated successfully. Sep 4 01:16:02.836448 bash[2473]: Updated "/home/core/.ssh/authorized_keys" Sep 4 01:16:02.836534 extend-filesystems[2409]: Resized filesystem in /dev/nvme0n1p9 Sep 4 01:16:02.825898 dbus-daemon[2403]: [system] SELinux support is enabled Sep 4 01:16:02.823106 systemd[1]: Finished extend-filesystems.service - Extend Filesystems. Sep 4 01:16:02.829108 systemd[1]: Started dbus.service - D-Bus System Message Bus. Sep 4 01:16:02.837723 systemd[1]: Finished update-ssh-keys-after-ignition.service - Run update-ssh-keys once after Ignition. Sep 4 01:16:02.841408 systemd[1]: sshkeys.service was skipped because no trigger condition checks were met. Sep 4 01:16:02.843041 systemd[1]: system-cloudinit@usr-share-oem-cloud\x2dconfig.yml.service - Load cloud-config from /usr/share/oem/cloud-config.yml was skipped because of an unmet condition check (ConditionFileNotEmpty=/usr/share/oem/cloud-config.yml). Sep 4 01:16:02.843918 systemd[1]: Reached target system-config.target - Load system-provided cloud configs. Sep 4 01:16:02.846168 systemd[1]: user-cloudinit-proc-cmdline.service - Load cloud-config from url defined in /proc/cmdline was skipped because of an unmet condition check (ConditionKernelCommandLine=cloud-config-url). Sep 4 01:16:02.846187 systemd[1]: Reached target user-config.target - Load user-provided cloud configs. Sep 4 01:16:02.849702 dbus-daemon[2403]: [system] Successfully activated service 'org.freedesktop.systemd1' Sep 4 01:16:02.854123 update_engine[2419]: I20260904 01:16:02.853829 2419 update_check_scheduler.cc:74] Next update check in 7m50s Sep 4 01:16:02.849946 systemd[1]: Started update-engine.service - Update Engine. Sep 4 01:16:02.863281 systemd[1]: Started locksmithd.service - Cluster reboot manager. Sep 4 01:16:02.956926 coreos-metadata[2402]: Sep 04 01:16:02.955 INFO Fetching http://168.63.129.16/?comp=versions: Attempt #1 Sep 4 01:16:02.958571 coreos-metadata[2402]: Sep 04 01:16:02.958 INFO Fetch successful Sep 4 01:16:02.959964 coreos-metadata[2402]: Sep 04 01:16:02.959 INFO Fetching http://168.63.129.16/machine/?comp=goalstate: Attempt #1 Sep 4 01:16:02.963032 coreos-metadata[2402]: Sep 04 01:16:02.963 INFO Fetch successful Sep 4 01:16:02.963032 coreos-metadata[2402]: Sep 04 01:16:02.963 INFO Fetching http://168.63.129.16/machine/cdbd6c93-b441-4631-873b-679f5347b7d1/0b9eb572%2D09f5%2D4c58%2Dbe34%2D2e5c13319d5b.%5Fci%2D4593.2.5%2Dn%2D471707002a?comp=config&type=sharedConfig&incarnation=1: Attempt #1 Sep 4 01:16:02.964034 coreos-metadata[2402]: Sep 04 01:16:02.963 INFO Fetch successful Sep 4 01:16:02.964034 coreos-metadata[2402]: Sep 04 01:16:02.963 INFO Fetching http://169.254.169.254/metadata/instance/compute/vmSize?api-version=2017-08-01&format=text: Attempt #1 Sep 4 01:16:02.970094 coreos-metadata[2402]: Sep 04 01:16:02.970 INFO Fetch successful Sep 4 01:16:02.998218 systemd[1]: Finished coreos-metadata.service - Flatcar Metadata Agent. Sep 4 01:16:02.999313 sshd_keygen[2448]: ssh-keygen: generating new host keys: RSA ECDSA ED25519 MLDSA44-ED25519 Sep 4 01:16:03.004637 systemd[1]: packet-phone-home.service - Report Success to Packet was skipped because no trigger condition checks were met. Sep 4 01:16:03.030416 systemd[1]: Finished sshd-keygen.service - Generate sshd host keys. Sep 4 01:16:03.033370 systemd[1]: Starting issuegen.service - Generate /run/issue... Sep 4 01:16:03.038001 systemd[1]: Starting waagent.service - Microsoft Azure Linux Agent... Sep 4 01:16:03.053736 systemd[1]: issuegen.service: Deactivated successfully. Sep 4 01:16:03.053954 systemd[1]: Finished issuegen.service - Generate /run/issue. Sep 4 01:16:03.061365 systemd[1]: Starting systemd-user-sessions.service - Permit User Sessions... Sep 4 01:16:03.070145 systemd[1]: Started waagent.service - Microsoft Azure Linux Agent. Sep 4 01:16:03.070430 locksmithd[2504]: locksmithd starting currentOperation="UPDATE_STATUS_IDLE" strategy="reboot" Sep 4 01:16:03.089252 systemd[1]: Finished systemd-user-sessions.service - Permit User Sessions. Sep 4 01:16:03.092081 systemd[1]: Started getty@tty1.service - Getty on tty1. Sep 4 01:16:03.095962 systemd[1]: Started serial-getty@ttyS0.service - Serial Getty on ttyS0. Sep 4 01:16:03.097826 systemd[1]: Reached target getty.target - Login Prompts. Sep 4 01:16:03.703105 containerd[2430]: time="2026-09-04T01:16:03Z" level=warning msg="Ignoring unknown key in TOML" column=1 error="strict mode: fields in the document are missing in the target struct" file=/usr/share/containerd/config.toml key=subreaper row=8 Sep 4 01:16:03.703665 containerd[2430]: time="2026-09-04T01:16:03.703636836Z" level=info msg="starting containerd" revision=fcd43222d6b07379a4be9786bda52438f0dd16a1 version=v2.1.5 Sep 4 01:16:03.710397 containerd[2430]: time="2026-09-04T01:16:03.710359344Z" level=warning msg="Configuration migrated from version 2, use `containerd config migrate` to avoid migration" t="8.044µs" Sep 4 01:16:03.710397 containerd[2430]: time="2026-09-04T01:16:03.710389578Z" level=info msg="loading plugin" id=io.containerd.content.v1.content type=io.containerd.content.v1 Sep 4 01:16:03.710516 containerd[2430]: time="2026-09-04T01:16:03.710426983Z" level=info msg="loading plugin" id=io.containerd.image-verifier.v1.bindir type=io.containerd.image-verifier.v1 Sep 4 01:16:03.710516 containerd[2430]: time="2026-09-04T01:16:03.710437834Z" level=info msg="loading plugin" id=io.containerd.internal.v1.opt type=io.containerd.internal.v1 Sep 4 01:16:03.710574 containerd[2430]: time="2026-09-04T01:16:03.710559354Z" level=info msg="loading plugin" id=io.containerd.warning.v1.deprecations type=io.containerd.warning.v1 Sep 4 01:16:03.710595 containerd[2430]: time="2026-09-04T01:16:03.710576907Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.blockfile type=io.containerd.snapshotter.v1 Sep 4 01:16:03.710643 containerd[2430]: time="2026-09-04T01:16:03.710620962Z" level=info msg="skip loading plugin" error="no scratch file generator: skip plugin" id=io.containerd.snapshotter.v1.blockfile type=io.containerd.snapshotter.v1 Sep 4 01:16:03.710666 containerd[2430]: time="2026-09-04T01:16:03.710641524Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.btrfs type=io.containerd.snapshotter.v1 Sep 4 01:16:03.710821 containerd[2430]: time="2026-09-04T01:16:03.710807842Z" level=info msg="skip loading plugin" error="path /var/lib/containerd/io.containerd.snapshotter.v1.btrfs (ext4) must be a btrfs filesystem to be used with the btrfs snapshotter: skip plugin" id=io.containerd.snapshotter.v1.btrfs type=io.containerd.snapshotter.v1 Sep 4 01:16:03.710862 containerd[2430]: time="2026-09-04T01:16:03.710819886Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.devmapper type=io.containerd.snapshotter.v1 Sep 4 01:16:03.710862 containerd[2430]: time="2026-09-04T01:16:03.710829780Z" level=info msg="skip loading plugin" error="devmapper not configured: skip plugin" id=io.containerd.snapshotter.v1.devmapper type=io.containerd.snapshotter.v1 Sep 4 01:16:03.710862 containerd[2430]: time="2026-09-04T01:16:03.710837162Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.erofs type=io.containerd.snapshotter.v1 Sep 4 01:16:03.710979 containerd[2430]: time="2026-09-04T01:16:03.710966626Z" level=info msg="skip loading plugin" error="EROFS unsupported, please `modprobe erofs`: skip plugin" id=io.containerd.snapshotter.v1.erofs type=io.containerd.snapshotter.v1 Sep 4 01:16:03.711005 containerd[2430]: time="2026-09-04T01:16:03.710979514Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.native type=io.containerd.snapshotter.v1 Sep 4 01:16:03.711062 containerd[2430]: time="2026-09-04T01:16:03.711048430Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.overlayfs type=io.containerd.snapshotter.v1 Sep 4 01:16:03.711185 containerd[2430]: time="2026-09-04T01:16:03.711170056Z" level=info msg="loading plugin" id=io.containerd.snapshotter.v1.zfs type=io.containerd.snapshotter.v1 Sep 4 01:16:03.711215 containerd[2430]: time="2026-09-04T01:16:03.711194599Z" level=info msg="skip loading plugin" error="lstat /var/lib/containerd/io.containerd.snapshotter.v1.zfs: no such file or directory: skip plugin" id=io.containerd.snapshotter.v1.zfs type=io.containerd.snapshotter.v1 Sep 4 01:16:03.711215 containerd[2430]: time="2026-09-04T01:16:03.711204020Z" level=info msg="loading plugin" id=io.containerd.event.v1.exchange type=io.containerd.event.v1 Sep 4 01:16:03.711254 containerd[2430]: time="2026-09-04T01:16:03.711238679Z" level=info msg="loading plugin" id=io.containerd.monitor.task.v1.cgroups type=io.containerd.monitor.task.v1 Sep 4 01:16:03.711485 containerd[2430]: time="2026-09-04T01:16:03.711463551Z" level=info msg="loading plugin" id=io.containerd.metadata.v1.bolt type=io.containerd.metadata.v1 Sep 4 01:16:03.711554 containerd[2430]: time="2026-09-04T01:16:03.711540344Z" level=info msg="metadata content store policy set" policy=shared Sep 4 01:16:03.727149 containerd[2430]: time="2026-09-04T01:16:03.727108473Z" level=info msg="loading plugin" id=io.containerd.gc.v1.scheduler type=io.containerd.gc.v1 Sep 4 01:16:03.727239 containerd[2430]: time="2026-09-04T01:16:03.727178689Z" level=info msg="loading plugin" id=io.containerd.differ.v1.erofs type=io.containerd.differ.v1 Sep 4 01:16:03.727380 containerd[2430]: time="2026-09-04T01:16:03.727362478Z" level=info msg="skip loading plugin" error="could not find mkfs.erofs: exec: \"mkfs.erofs\": executable file not found in $PATH: skip plugin" id=io.containerd.differ.v1.erofs type=io.containerd.differ.v1 Sep 4 01:16:03.727414 containerd[2430]: time="2026-09-04T01:16:03.727382481Z" level=info msg="loading plugin" id=io.containerd.differ.v1.walking type=io.containerd.differ.v1 Sep 4 01:16:03.727414 containerd[2430]: time="2026-09-04T01:16:03.727396695Z" level=info msg="loading plugin" id=io.containerd.lease.v1.manager type=io.containerd.lease.v1 Sep 4 01:16:03.727414 containerd[2430]: time="2026-09-04T01:16:03.727408407Z" level=info msg="loading plugin" id=io.containerd.service.v1.containers-service type=io.containerd.service.v1 Sep 4 01:16:03.727468 containerd[2430]: time="2026-09-04T01:16:03.727421118Z" level=info msg="loading plugin" id=io.containerd.service.v1.content-service type=io.containerd.service.v1 Sep 4 01:16:03.727468 containerd[2430]: time="2026-09-04T01:16:03.727436340Z" level=info msg="loading plugin" id=io.containerd.service.v1.diff-service type=io.containerd.service.v1 Sep 4 01:16:03.727468 containerd[2430]: time="2026-09-04T01:16:03.727449138Z" level=info msg="loading plugin" id=io.containerd.service.v1.images-service type=io.containerd.service.v1 Sep 4 01:16:03.727468 containerd[2430]: time="2026-09-04T01:16:03.727461015Z" level=info msg="loading plugin" id=io.containerd.service.v1.introspection-service type=io.containerd.service.v1 Sep 4 01:16:03.727538 containerd[2430]: time="2026-09-04T01:16:03.727471869Z" level=info msg="loading plugin" id=io.containerd.service.v1.namespaces-service type=io.containerd.service.v1 Sep 4 01:16:03.727538 containerd[2430]: time="2026-09-04T01:16:03.727489650Z" level=info msg="loading plugin" id=io.containerd.service.v1.snapshots-service type=io.containerd.service.v1 Sep 4 01:16:03.727538 containerd[2430]: time="2026-09-04T01:16:03.727501774Z" level=info msg="loading plugin" id=io.containerd.shim.v1.manager type=io.containerd.shim.v1 Sep 4 01:16:03.727538 containerd[2430]: time="2026-09-04T01:16:03.727513940Z" level=info msg="loading plugin" id=io.containerd.runtime.v2.task type=io.containerd.runtime.v2 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727620884Z" level=info msg="loading plugin" id=io.containerd.service.v1.tasks-service type=io.containerd.service.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727640817Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.containers type=io.containerd.grpc.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727654805Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.content type=io.containerd.grpc.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727664960Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.diff type=io.containerd.grpc.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727674810Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.events type=io.containerd.grpc.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727684020Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.images type=io.containerd.grpc.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727695092Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.introspection type=io.containerd.grpc.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727706305Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.leases type=io.containerd.grpc.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727716623Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.namespaces type=io.containerd.grpc.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727728190Z" level=info msg="loading plugin" id=io.containerd.sandbox.store.v1.local type=io.containerd.sandbox.store.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727745506Z" level=info msg="loading plugin" id=io.containerd.transfer.v1.local type=io.containerd.transfer.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727770087Z" level=info msg="loading plugin" id=io.containerd.cri.v1.images type=io.containerd.cri.v1 Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727818584Z" level=info msg="Get image filesystem path \"/var/lib/containerd/io.containerd.snapshotter.v1.overlayfs\" for snapshotter \"overlayfs\"" Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727834441Z" level=info msg="Start snapshots syncer" Sep 4 01:16:03.728495 containerd[2430]: time="2026-09-04T01:16:03.727879664Z" level=info msg="loading plugin" id=io.containerd.cri.v1.runtime type=io.containerd.cri.v1 Sep 4 01:16:03.728816 containerd[2430]: time="2026-09-04T01:16:03.728134056Z" level=info msg="starting cri plugin" config="{\"containerd\":{\"defaultRuntimeName\":\"runc\",\"runtimes\":{\"runc\":{\"runtimeType\":\"io.containerd.runc.v2\",\"runtimePath\":\"\",\"PodAnnotations\":null,\"ContainerAnnotations\":null,\"options\":{\"BinaryName\":\"\",\"CriuImagePath\":\"\",\"CriuWorkPath\":\"\",\"IoGid\":0,\"IoUid\":0,\"NoNewKeyring\":false,\"Root\":\"\",\"ShimCgroup\":\"\",\"SystemdCgroup\":true},\"privileged_without_host_devices\":false,\"privileged_without_host_devices_all_devices_allowed\":false,\"cgroupWritable\":false,\"baseRuntimeSpec\":\"\",\"cniConfDir\":\"\",\"cniMaxConfNum\":0,\"snapshotter\":\"\",\"sandboxer\":\"podsandbox\",\"io_type\":\"\"}},\"ignoreBlockIONotEnabledErrors\":false,\"ignoreRdtNotEnabledErrors\":false},\"cni\":{\"binDir\":\"\",\"binDirs\":[\"/opt/cni/bin\"],\"confDir\":\"/etc/cni/net.d\",\"maxConfNum\":1,\"setupSerially\":false,\"confTemplate\":\"\",\"ipPref\":\"\",\"useInternalLoopback\":false},\"enableSelinux\":true,\"selinuxCategoryRange\":1024,\"maxContainerLogLineSize\":16384,\"disableApparmor\":false,\"restrictOOMScoreAdj\":false,\"disableProcMount\":false,\"unsetSeccompProfile\":\"\",\"tolerateMissingHugetlbController\":true,\"disableHugetlbController\":true,\"device_ownership_from_security_context\":false,\"ignoreImageDefinedVolumes\":false,\"netnsMountsUnderStateDir\":false,\"enableUnprivilegedPorts\":true,\"enableUnprivilegedICMP\":true,\"enableCDI\":true,\"cdiSpecDirs\":[\"/etc/cdi\",\"/var/run/cdi\"],\"drainExecSyncIOTimeout\":\"0s\",\"ignoreDeprecationWarnings\":null,\"containerdRootDir\":\"/var/lib/containerd\",\"containerdEndpoint\":\"/run/containerd/containerd.sock\",\"rootDir\":\"/var/lib/containerd/io.containerd.grpc.v1.cri\",\"stateDir\":\"/run/containerd/io.containerd.grpc.v1.cri\"}" Sep 4 01:16:03.728816 containerd[2430]: time="2026-09-04T01:16:03.728183531Z" level=info msg="loading plugin" id=io.containerd.podsandbox.controller.v1.podsandbox type=io.containerd.podsandbox.controller.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728240828Z" level=info msg="loading plugin" id=io.containerd.sandbox.controller.v1.shim type=io.containerd.sandbox.controller.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728329970Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.sandbox-controllers type=io.containerd.grpc.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728347651Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.sandboxes type=io.containerd.grpc.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728357836Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.snapshots type=io.containerd.grpc.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728367469Z" level=info msg="loading plugin" id=io.containerd.streaming.v1.manager type=io.containerd.streaming.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728380076Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.streaming type=io.containerd.grpc.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728396217Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.tasks type=io.containerd.grpc.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728407397Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.transfer type=io.containerd.grpc.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728418748Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.version type=io.containerd.grpc.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728429473Z" level=info msg="loading plugin" id=io.containerd.monitor.container.v1.restart type=io.containerd.monitor.container.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728451044Z" level=info msg="loading plugin" id=io.containerd.tracing.processor.v1.otlp type=io.containerd.tracing.processor.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728465030Z" level=info msg="skip loading plugin" error="skip plugin: tracing endpoint not configured" id=io.containerd.tracing.processor.v1.otlp type=io.containerd.tracing.processor.v1 Sep 4 01:16:03.728956 containerd[2430]: time="2026-09-04T01:16:03.728474734Z" level=info msg="loading plugin" id=io.containerd.internal.v1.tracing type=io.containerd.internal.v1 Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.728483896Z" level=info msg="skip loading plugin" error="skip plugin: tracing endpoint not configured" id=io.containerd.internal.v1.tracing type=io.containerd.internal.v1 Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.728492154Z" level=info msg="loading plugin" id=io.containerd.ttrpc.v1.otelttrpc type=io.containerd.ttrpc.v1 Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.728942695Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.healthcheck type=io.containerd.grpc.v1 Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.728970834Z" level=info msg="loading plugin" id=io.containerd.nri.v1.nri type=io.containerd.nri.v1 Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.728992044Z" level=info msg="runtime interface created" Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.728998554Z" level=info msg="created NRI interface" Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.729013235Z" level=info msg="loading plugin" id=io.containerd.grpc.v1.cri type=io.containerd.grpc.v1 Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.729032308Z" level=info msg="Connect containerd service" Sep 4 01:16:03.729189 containerd[2430]: time="2026-09-04T01:16:03.729063961Z" level=info msg="using experimental NRI integration - disable nri plugin to prevent this" Sep 4 01:16:03.731836 containerd[2430]: time="2026-09-04T01:16:03.731036621Z" level=error msg="failed to load cni during init, please check CRI plugin status before setting up network for pods" error="cni config load failed: no network config found in /etc/cni/net.d: cni plugin not initialized: failed to load cni config" Sep 4 01:16:04.144497 waagent[2538]: 2026-09-04T01:16:04.141794Z INFO Daemon Daemon Azure Linux Agent Version: 2.12.0.4 Sep 4 01:16:04.146684 waagent[2538]: 2026-09-04T01:16:04.144957Z INFO Daemon Daemon OS: flatcar 4593.2.5 Sep 4 01:16:04.146864 waagent[2538]: 2026-09-04T01:16:04.146810Z INFO Daemon Daemon Python: 3.12.11 Sep 4 01:16:04.147998 waagent[2538]: 2026-09-04T01:16:04.147943Z INFO Daemon Daemon Run daemon Sep 4 01:16:04.151038 waagent[2538]: 2026-09-04T01:16:04.150989Z INFO Daemon Daemon No RDMA handler exists for distro='Flatcar Container Linux by Kinvolk' version='4593.2.5' Sep 4 01:16:04.154931 waagent[2538]: 2026-09-04T01:16:04.154891Z INFO Daemon Daemon Using waagent for provisioning Sep 4 01:16:04.156151 waagent[2538]: 2026-09-04T01:16:04.156118Z INFO Daemon Daemon Activate resource disk Sep 4 01:16:04.157382 waagent[2538]: 2026-09-04T01:16:04.157349Z INFO Daemon Daemon Searching gen1 prefix 00000000-0001 or gen2 f8b3781a-1e82-4818-a1c3-63d806ec15bb Sep 4 01:16:04.160322 waagent[2538]: 2026-09-04T01:16:04.160277Z INFO Daemon Daemon Found device: None Sep 4 01:16:04.162951 waagent[2538]: 2026-09-04T01:16:04.162895Z ERROR Daemon Daemon Failed to mount resource disk [ResourceDiskError] unable to detect disk topology Sep 4 01:16:04.166993 waagent[2538]: 2026-09-04T01:16:04.166948Z ERROR Daemon Daemon Event: name=WALinuxAgent, op=ActivateResourceDisk, message=[ResourceDiskError] unable to detect disk topology, duration=0 Sep 4 01:16:04.170382 waagent[2538]: 2026-09-04T01:16:04.170344Z INFO Daemon Daemon Clean protocol and wireserver endpoint Sep 4 01:16:04.173982 waagent[2538]: 2026-09-04T01:16:04.173948Z INFO Daemon Daemon Running default provisioning handler Sep 4 01:16:04.182385 waagent[2538]: 2026-09-04T01:16:04.182338Z INFO Daemon Daemon Unable to get cloud-init enabled status from systemctl: Command '['systemctl', 'is-enabled', 'cloud-init-local.service']' returned non-zero exit status 4. Sep 4 01:16:04.188941 waagent[2538]: 2026-09-04T01:16:04.188895Z INFO Daemon Daemon Unable to get cloud-init enabled status from service: [Errno 2] No such file or directory: 'service' Sep 4 01:16:04.192973 waagent[2538]: 2026-09-04T01:16:04.192904Z INFO Daemon Daemon cloud-init is enabled: False Sep 4 01:16:04.193907 waagent[2538]: 2026-09-04T01:16:04.193876Z INFO Daemon Daemon Copying ovf-env.xml Sep 4 01:16:04.218024 containerd[2430]: time="2026-09-04T01:16:04.217985670Z" level=info msg=serving... address=/run/containerd/containerd.sock.ttrpc Sep 4 01:16:04.218096 containerd[2430]: time="2026-09-04T01:16:04.218037453Z" level=info msg=serving... address=/run/containerd/containerd.sock Sep 4 01:16:04.218096 containerd[2430]: time="2026-09-04T01:16:04.218059553Z" level=info msg="Start subscribing containerd event" Sep 4 01:16:04.218131 containerd[2430]: time="2026-09-04T01:16:04.218084714Z" level=info msg="Start recovering state" Sep 4 01:16:04.222151 containerd[2430]: time="2026-09-04T01:16:04.218174508Z" level=info msg="Start event monitor" Sep 4 01:16:04.222151 containerd[2430]: time="2026-09-04T01:16:04.218188890Z" level=info msg="Start cni network conf syncer for default" Sep 4 01:16:04.222151 containerd[2430]: time="2026-09-04T01:16:04.218196986Z" level=info msg="Start streaming server" Sep 4 01:16:04.222151 containerd[2430]: time="2026-09-04T01:16:04.218204913Z" level=info msg="Registered namespace \"k8s.io\" with NRI" Sep 4 01:16:04.222151 containerd[2430]: time="2026-09-04T01:16:04.218212687Z" level=info msg="runtime interface starting up..." Sep 4 01:16:04.222151 containerd[2430]: time="2026-09-04T01:16:04.218219004Z" level=info msg="starting plugins..." Sep 4 01:16:04.222151 containerd[2430]: time="2026-09-04T01:16:04.218230743Z" level=info msg="Synchronizing NRI (plugin) with current runtime state" Sep 4 01:16:04.222151 containerd[2430]: time="2026-09-04T01:16:04.218318610Z" level=info msg="containerd successfully booted in 0.515623s" Sep 4 01:16:04.218636 systemd[1]: Started containerd.service - containerd container runtime. Sep 4 01:16:04.220536 systemd[1]: Reached target multi-user.target - Multi-User System. Sep 4 01:16:04.224257 systemd[1]: Startup finished in 4.133s (kernel) + 8.612s (initrd) + 13.697s (userspace) = 26.443s. Sep 4 01:16:04.283860 waagent[2538]: 2026-09-04T01:16:04.282188Z INFO Daemon Daemon Successfully mounted dvd Sep 4 01:16:04.308830 systemd[1]: mnt-cdrom-secure.mount: Deactivated successfully. Sep 4 01:16:04.311165 waagent[2538]: 2026-09-04T01:16:04.311110Z INFO Daemon Daemon Detect protocol endpoint Sep 4 01:16:04.312344 waagent[2538]: 2026-09-04T01:16:04.312307Z INFO Daemon Daemon Clean protocol and wireserver endpoint Sep 4 01:16:04.313731 waagent[2538]: 2026-09-04T01:16:04.313701Z INFO Daemon Daemon WireServer endpoint is not found. Rerun dhcp handler Sep 4 01:16:04.315216 waagent[2538]: 2026-09-04T01:16:04.315154Z INFO Daemon Daemon Test for route to 168.63.129.16 Sep 4 01:16:04.316535 waagent[2538]: 2026-09-04T01:16:04.316502Z INFO Daemon Daemon Route to 168.63.129.16 exists Sep 4 01:16:04.317696 waagent[2538]: 2026-09-04T01:16:04.317633Z INFO Daemon Daemon Wire server endpoint:168.63.129.16 Sep 4 01:16:04.331470 waagent[2538]: 2026-09-04T01:16:04.331437Z INFO Daemon Daemon Fabric preferred wire protocol version:2015-04-05 Sep 4 01:16:04.332728 waagent[2538]: 2026-09-04T01:16:04.332081Z INFO Daemon Daemon Wire protocol version:2012-11-30 Sep 4 01:16:04.332728 waagent[2538]: 2026-09-04T01:16:04.332452Z INFO Daemon Daemon Server preferred version:2015-04-05 Sep 4 01:16:04.414605 waagent[2538]: 2026-09-04T01:16:04.414474Z INFO Daemon Daemon Initializing goal state during protocol detection Sep 4 01:16:04.415135 waagent[2538]: 2026-09-04T01:16:04.414968Z INFO Daemon Daemon Forcing an update of the goal state. Sep 4 01:16:04.418645 waagent[2538]: 2026-09-04T01:16:04.418601Z INFO Daemon Fetched a new incarnation for the WireServer goal state [incarnation 1] Sep 4 01:16:04.430591 waagent[2538]: 2026-09-04T01:16:04.430560Z INFO Daemon Daemon HostGAPlugin version: 1.0.8.185 Sep 4 01:16:04.433549 waagent[2538]: 2026-09-04T01:16:04.431422Z INFO Daemon Sep 4 01:16:04.433549 waagent[2538]: 2026-09-04T01:16:04.431918Z INFO Daemon Fetched new vmSettings [HostGAPlugin correlation ID: 2a564b5d-e80d-4916-b1b5-32ede1804048 eTag: 11759247693892795133 source: Fabric] Sep 4 01:16:04.433549 waagent[2538]: 2026-09-04T01:16:04.432358Z INFO Daemon The vmSettings originated via Fabric; will ignore them. Sep 4 01:16:04.433549 waagent[2538]: 2026-09-04T01:16:04.432709Z INFO Daemon Sep 4 01:16:04.433549 waagent[2538]: 2026-09-04T01:16:04.432975Z INFO Daemon Fetching full goal state from the WireServer [incarnation 1] Sep 4 01:16:04.439108 waagent[2538]: 2026-09-04T01:16:04.439080Z INFO Daemon Daemon Downloading artifacts profile blob Sep 4 01:16:04.504177 login[2540]: pam_unix(login:session): session opened for user core(uid=500) by LOGIN(uid=0) Sep 4 01:16:04.517912 waagent[2538]: 2026-09-04T01:16:04.514347Z INFO Daemon Downloaded certificate {'thumbprint': '8BFF29C71B23FDEF56F565839BE5BB9ACDC788EC', 'hasPrivateKey': True} Sep 4 01:16:04.514806 systemd[1]: Created slice user-500.slice - User Slice of UID 500. Sep 4 01:16:04.518153 systemd[1]: Starting user-runtime-dir@500.service - User Runtime Directory /run/user/500... Sep 4 01:16:04.518687 waagent[2538]: 2026-09-04T01:16:04.518645Z INFO Daemon Fetch goal state completed Sep 4 01:16:04.522861 systemd-logind[2416]: New session 1 of user core. Sep 4 01:16:04.525477 waagent[2538]: 2026-09-04T01:16:04.525445Z INFO Daemon Daemon Starting provisioning Sep 4 01:16:04.526494 waagent[2538]: 2026-09-04T01:16:04.526452Z INFO Daemon Daemon Handle ovf-env.xml. Sep 4 01:16:04.528778 waagent[2538]: 2026-09-04T01:16:04.526881Z INFO Daemon Daemon Set hostname [ci-4593.2.5-n-471707002a] Sep 4 01:16:04.550724 systemd[1]: Finished user-runtime-dir@500.service - User Runtime Directory /run/user/500. Sep 4 01:16:04.552818 systemd[1]: Starting user@500.service - User Manager for UID 500... Sep 4 01:16:04.562446 (systemd)[2581]: pam_unix(systemd-user:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:04.566985 systemd-logind[2416]: New session 2 of user core. Sep 4 01:16:04.570162 waagent[2538]: 2026-09-04T01:16:04.569415Z INFO Daemon Daemon Publish hostname [ci-4593.2.5-n-471707002a] Sep 4 01:16:04.571679 waagent[2538]: 2026-09-04T01:16:04.571634Z INFO Daemon Daemon Examine /proc/net/route for primary interface Sep 4 01:16:04.574101 waagent[2538]: 2026-09-04T01:16:04.573636Z INFO Daemon Daemon Primary interface is [eth0] Sep 4 01:16:04.579633 login[2541]: pam_unix(login:session): session opened for user core(uid=500) by LOGIN(uid=0) Sep 4 01:16:04.594318 systemd-networkd[2174]: eth0: Found matching .network file, based on potentially unpredictable interface name: /usr/lib/systemd/network/zz-default.network Sep 4 01:16:04.594326 systemd-networkd[2174]: eth0: Reconfiguring with /usr/lib/systemd/network/zz-default.network. Sep 4 01:16:04.594397 systemd-networkd[2174]: eth0: DHCP lease lost Sep 4 01:16:04.594644 systemd-logind[2416]: New session 3 of user core. Sep 4 01:16:04.610715 waagent[2538]: 2026-09-04T01:16:04.610642Z INFO Daemon Daemon Create user account if not exists Sep 4 01:16:04.616866 waagent[2538]: 2026-09-04T01:16:04.611267Z INFO Daemon Daemon User core already exists, skip useradd Sep 4 01:16:04.616866 waagent[2538]: 2026-09-04T01:16:04.611507Z INFO Daemon Daemon Configure sudoer Sep 4 01:16:04.616866 waagent[2538]: 2026-09-04T01:16:04.612018Z INFO Daemon Daemon Configure sshd Sep 4 01:16:04.616866 waagent[2538]: 2026-09-04T01:16:04.612242Z INFO Daemon Daemon Added a configuration snippet disabling SSH password-based authentication methods. It also configures SSH client probing to keep connections alive. Sep 4 01:16:04.616866 waagent[2538]: 2026-09-04T01:16:04.612391Z INFO Daemon Daemon Deploy ssh public key. Sep 4 01:16:04.621881 systemd-networkd[2174]: eth0: DHCPv4 address 10.0.0.35/24, gateway 10.0.0.1 acquired from 168.63.129.16 Sep 4 01:16:04.725592 systemd[2581]: Queued start job for default target default.target. Sep 4 01:16:04.730551 systemd[2581]: Created slice app.slice - User Application Slice. Sep 4 01:16:04.730581 systemd[2581]: Started systemd-tmpfiles-clean.timer - Daily Cleanup of User's Temporary Directories. Sep 4 01:16:04.730594 systemd[2581]: Reached target paths.target - Paths. Sep 4 01:16:04.730637 systemd[2581]: Reached target timers.target - Timers. Sep 4 01:16:04.731744 systemd[2581]: Starting dbus.socket - D-Bus User Message Bus Socket... Sep 4 01:16:04.732393 systemd[2581]: Starting systemd-tmpfiles-setup.service - Create User Files and Directories... Sep 4 01:16:04.743658 systemd[2581]: Listening on dbus.socket - D-Bus User Message Bus Socket. Sep 4 01:16:04.743970 systemd[2581]: Finished systemd-tmpfiles-setup.service - Create User Files and Directories. Sep 4 01:16:04.744613 systemd[2581]: Reached target sockets.target - Sockets. Sep 4 01:16:04.744723 systemd[2581]: Reached target basic.target - Basic System. Sep 4 01:16:04.744818 systemd[2581]: Reached target default.target - Main User Target. Sep 4 01:16:04.744856 systemd[1]: Started user@500.service - User Manager for UID 500. Sep 4 01:16:04.744858 systemd[2581]: Startup finished in 154ms. Sep 4 01:16:04.750046 systemd[1]: Started session-1.scope - Session 1 of User core. Sep 4 01:16:04.750543 systemd[1]: Started session-3.scope - Session 3 of User core. Sep 4 01:16:05.728135 waagent[2538]: 2026-09-04T01:16:05.728080Z INFO Daemon Daemon Provisioning complete Sep 4 01:16:05.735232 waagent[2538]: 2026-09-04T01:16:05.735200Z INFO Daemon Daemon RDMA capabilities are not enabled, skipping Sep 4 01:16:05.737103 waagent[2538]: 2026-09-04T01:16:05.735869Z INFO Daemon Daemon End of log to /dev/console. The agent will now check for updates and then will process extensions. Sep 4 01:16:05.737103 waagent[2538]: 2026-09-04T01:16:05.736189Z INFO Daemon Daemon Installed Agent WALinuxAgent-2.12.0.4 is the most current agent Sep 4 01:16:05.847293 waagent[2621]: 2026-09-04T01:16:05.847205Z INFO ExtHandler ExtHandler Azure Linux Agent (Goal State Agent version 2.12.0.4) Sep 4 01:16:05.847616 waagent[2621]: 2026-09-04T01:16:05.847340Z INFO ExtHandler ExtHandler OS: flatcar 4593.2.5 Sep 4 01:16:05.847616 waagent[2621]: 2026-09-04T01:16:05.847393Z INFO ExtHandler ExtHandler Python: 3.12.11 Sep 4 01:16:05.847616 waagent[2621]: 2026-09-04T01:16:05.847434Z INFO ExtHandler ExtHandler CPU Arch: x86_64 Sep 4 01:16:05.871694 waagent[2621]: 2026-09-04T01:16:05.871636Z INFO ExtHandler ExtHandler Distro: flatcar-4593.2.5; OSUtil: FlatcarUtil; AgentService: waagent; Python: 3.12.11; Arch: x86_64; systemd: True; LISDrivers: Absent; logrotate: logrotate 3.22.0; Sep 4 01:16:05.871837 waagent[2621]: 2026-09-04T01:16:05.871813Z INFO ExtHandler ExtHandler WireServer endpoint 168.63.129.16 read from file Sep 4 01:16:05.871929 waagent[2621]: 2026-09-04T01:16:05.871891Z INFO ExtHandler ExtHandler Wire server endpoint:168.63.129.16 Sep 4 01:16:05.880282 waagent[2621]: 2026-09-04T01:16:05.880227Z INFO ExtHandler Fetched a new incarnation for the WireServer goal state [incarnation 1] Sep 4 01:16:05.885615 waagent[2621]: 2026-09-04T01:16:05.885574Z INFO ExtHandler ExtHandler HostGAPlugin version: 1.0.8.185 Sep 4 01:16:05.886023 waagent[2621]: 2026-09-04T01:16:05.885993Z INFO ExtHandler Sep 4 01:16:05.886085 waagent[2621]: 2026-09-04T01:16:05.886065Z INFO ExtHandler Fetched new vmSettings [HostGAPlugin correlation ID: 6d971af0-c127-4d63-8311-021a1a2fcea9 eTag: 11759247693892795133 source: Fabric] Sep 4 01:16:05.886309 waagent[2621]: 2026-09-04T01:16:05.886284Z INFO ExtHandler The vmSettings originated via Fabric; will ignore them. Sep 4 01:16:05.886671 waagent[2621]: 2026-09-04T01:16:05.886645Z INFO ExtHandler Sep 4 01:16:05.886711 waagent[2621]: 2026-09-04T01:16:05.886697Z INFO ExtHandler Fetching full goal state from the WireServer [incarnation 1] Sep 4 01:16:05.896092 waagent[2621]: 2026-09-04T01:16:05.896064Z INFO ExtHandler ExtHandler Downloading artifacts profile blob Sep 4 01:16:05.960442 waagent[2621]: 2026-09-04T01:16:05.960383Z INFO ExtHandler Downloaded certificate {'thumbprint': '8BFF29C71B23FDEF56F565839BE5BB9ACDC788EC', 'hasPrivateKey': True} Sep 4 01:16:05.960799 waagent[2621]: 2026-09-04T01:16:05.960770Z INFO ExtHandler Fetch goal state completed Sep 4 01:16:05.975762 waagent[2621]: 2026-09-04T01:16:05.975705Z INFO ExtHandler ExtHandler OpenSSL version: OpenSSL 3.5.5 27 Jan 2026 (Library: OpenSSL 3.5.5 27 Jan 2026) Sep 4 01:16:05.980520 waagent[2621]: 2026-09-04T01:16:05.980437Z INFO ExtHandler ExtHandler WALinuxAgent-2.12.0.4 running as process 2621 Sep 4 01:16:05.980620 waagent[2621]: 2026-09-04T01:16:05.980580Z INFO ExtHandler ExtHandler ******** AutoUpdate.Enabled is set to False, not processing the operation ******** Sep 4 01:16:05.980911 waagent[2621]: 2026-09-04T01:16:05.980884Z INFO ExtHandler ExtHandler ******** AutoUpdate.UpdateToLatestVersion is set to False, not processing the operation ******** Sep 4 01:16:05.982019 waagent[2621]: 2026-09-04T01:16:05.981986Z INFO ExtHandler ExtHandler [CGI] Cgroup monitoring is not supported on ['flatcar', '4593.2.5', '', 'Flatcar Container Linux by Kinvolk'] Sep 4 01:16:05.982305 waagent[2621]: 2026-09-04T01:16:05.982280Z INFO ExtHandler ExtHandler [CGI] Agent will reset the quotas in case distro: ['flatcar', '4593.2.5', '', 'Flatcar Container Linux by Kinvolk'] went from supported to unsupported Sep 4 01:16:05.982424 waagent[2621]: 2026-09-04T01:16:05.982405Z INFO ExtHandler ExtHandler [CGI] Agent cgroups enabled: False Sep 4 01:16:05.982852 waagent[2621]: 2026-09-04T01:16:05.982818Z INFO ExtHandler ExtHandler Starting setup for Persistent firewall rules Sep 4 01:16:06.049702 waagent[2621]: 2026-09-04T01:16:06.049665Z INFO ExtHandler ExtHandler Firewalld service not running/unavailable, trying to set up waagent-network-setup.service Sep 4 01:16:06.049913 waagent[2621]: 2026-09-04T01:16:06.049888Z INFO ExtHandler ExtHandler Successfully updated the Binary file /var/lib/waagent/waagent-network-setup.py for firewall setup Sep 4 01:16:06.055418 waagent[2621]: 2026-09-04T01:16:06.055387Z INFO ExtHandler ExtHandler Service: waagent-network-setup.service not enabled. Adding it now Sep 4 01:16:06.060479 systemd[1]: Reload requested from client PID 2636 ('systemctl') (unit waagent.service)... Sep 4 01:16:06.060493 systemd[1]: Reloading... Sep 4 01:16:06.120869 zram_generator::config[2676]: No configuration found. Sep 4 01:16:06.313440 systemd[1]: Reloading finished in 252 ms. Sep 4 01:16:06.330867 waagent[2621]: 2026-09-04T01:16:06.329685Z INFO ExtHandler ExtHandler Successfully added and enabled the waagent-network-setup.service Sep 4 01:16:06.330867 waagent[2621]: 2026-09-04T01:16:06.329858Z INFO ExtHandler ExtHandler Persistent firewall rules setup successfully Sep 4 01:16:06.367866 kernel: hv_storvsc f8b3781a-1e82-4818-a1c3-63d806ec15bb: tag#56 cmd 0x4a status: scsi 0x0 srb 0x20 hv 0xc0000001 Sep 4 01:16:06.772285 waagent[2621]: 2026-09-04T01:16:06.772216Z INFO ExtHandler ExtHandler DROP rule is not available which implies no firewall rules are set yet. Environment thread will set it up. Sep 4 01:16:06.772548 waagent[2621]: 2026-09-04T01:16:06.772523Z INFO ExtHandler ExtHandler Checking if log collection is allowed at this time [False]. All three conditions must be met: 1. configuration enabled [True], 2. cgroups v1 enabled [False] OR cgroups v2 is in use and v2 resource limiting configuration enabled [False], 3. python supported: [True] Sep 4 01:16:06.773184 waagent[2621]: 2026-09-04T01:16:06.773121Z INFO ExtHandler ExtHandler Starting env monitor service. Sep 4 01:16:06.773555 waagent[2621]: 2026-09-04T01:16:06.773521Z INFO MonitorHandler ExtHandler WireServer endpoint 168.63.129.16 read from file Sep 4 01:16:06.773594 waagent[2621]: 2026-09-04T01:16:06.773576Z INFO ExtHandler ExtHandler Start SendTelemetryHandler service. Sep 4 01:16:06.773899 waagent[2621]: 2026-09-04T01:16:06.773837Z INFO MonitorHandler ExtHandler Wire server endpoint:168.63.129.16 Sep 4 01:16:06.774005 waagent[2621]: 2026-09-04T01:16:06.773904Z INFO SendTelemetryHandler ExtHandler Successfully started the SendTelemetryHandler thread Sep 4 01:16:06.774005 waagent[2621]: 2026-09-04T01:16:06.773971Z INFO EnvHandler ExtHandler WireServer endpoint 168.63.129.16 read from file Sep 4 01:16:06.774183 waagent[2621]: 2026-09-04T01:16:06.774162Z INFO ExtHandler ExtHandler Start Extension Telemetry service. Sep 4 01:16:06.774322 waagent[2621]: 2026-09-04T01:16:06.774301Z INFO EnvHandler ExtHandler Wire server endpoint:168.63.129.16 Sep 4 01:16:06.774606 waagent[2621]: 2026-09-04T01:16:06.774576Z INFO TelemetryEventsCollector ExtHandler Extension Telemetry pipeline enabled: True Sep 4 01:16:06.774745 waagent[2621]: 2026-09-04T01:16:06.774718Z INFO EnvHandler ExtHandler Configure routes Sep 4 01:16:06.774964 waagent[2621]: 2026-09-04T01:16:06.774940Z INFO MonitorHandler ExtHandler Monitor.NetworkConfigurationChanges is disabled. Sep 4 01:16:06.775049 waagent[2621]: 2026-09-04T01:16:06.775015Z INFO ExtHandler ExtHandler Goal State Period: 6 sec. This indicates how often the agent checks for new goal states and reports status. Sep 4 01:16:06.775145 waagent[2621]: 2026-09-04T01:16:06.775119Z INFO TelemetryEventsCollector ExtHandler Successfully started the TelemetryEventsCollector thread Sep 4 01:16:06.775924 waagent[2621]: 2026-09-04T01:16:06.775876Z INFO EnvHandler ExtHandler Gateway:None Sep 4 01:16:06.776100 waagent[2621]: 2026-09-04T01:16:06.776074Z INFO MonitorHandler ExtHandler Routing table from /proc/net/route: Sep 4 01:16:06.776100 waagent[2621]: Iface Destination Gateway Flags RefCnt Use Metric Mask MTU Window IRTT Sep 4 01:16:06.776100 waagent[2621]: eth0 00000000 0100000A 0003 0 0 1024 00000000 0 0 0 Sep 4 01:16:06.776100 waagent[2621]: eth0 0000000A 00000000 0001 0 0 1024 00FFFFFF 0 0 0 Sep 4 01:16:06.776100 waagent[2621]: eth0 0100000A 00000000 0005 0 0 1024 FFFFFFFF 0 0 0 Sep 4 01:16:06.776100 waagent[2621]: eth0 10813FA8 0100000A 0007 0 0 1024 FFFFFFFF 0 0 0 Sep 4 01:16:06.776100 waagent[2621]: eth0 FEA9FEA9 0100000A 0007 0 0 1024 FFFFFFFF 0 0 0 Sep 4 01:16:06.777015 waagent[2621]: 2026-09-04T01:16:06.776985Z INFO EnvHandler ExtHandler Routes:None Sep 4 01:16:06.786865 waagent[2621]: 2026-09-04T01:16:06.785966Z INFO ExtHandler ExtHandler Sep 4 01:16:06.786865 waagent[2621]: 2026-09-04T01:16:06.786018Z INFO ExtHandler ExtHandler ProcessExtensionsGoalState started [incarnation_1 channel: WireServer source: Fabric activity: 0c908b58-33d1-4970-b291-65bd181c8dd9 correlation 8348d821-7fe8-400e-a5e6-b71ce101f6c2 created: 2026-09-04T01:15:15.669807Z] Sep 4 01:16:06.786865 waagent[2621]: 2026-09-04T01:16:06.786223Z INFO ExtHandler ExtHandler No extension handlers found, not processing anything. Sep 4 01:16:06.786865 waagent[2621]: 2026-09-04T01:16:06.786565Z INFO ExtHandler ExtHandler ProcessExtensionsGoalState completed [incarnation_1 0 ms] Sep 4 01:16:06.813057 waagent[2621]: 2026-09-04T01:16:06.813015Z WARNING ExtHandler ExtHandler Failed to get firewall packets: 'iptables -w -t security -L OUTPUT --zero OUTPUT -nxv' failed: 2 (iptables v1.8.11 (nf_tables): Illegal option `--numeric' with this command Sep 4 01:16:06.813057 waagent[2621]: Try `iptables -h' or 'iptables --help' for more information.) Sep 4 01:16:06.813366 waagent[2621]: 2026-09-04T01:16:06.813341Z INFO ExtHandler ExtHandler [HEARTBEAT] Agent WALinuxAgent-2.12.0.4 is running as the goal state agent [DEBUG HeartbeatCounter: 0;HeartbeatId: 78BC1F62-9E5B-4AE6-B823-FA99E3DD07D0;DroppedPackets: -1;UpdateGSErrors: 0;AutoUpdate: 0;UpdateMode: SelfUpdate;] Sep 4 01:16:06.852484 waagent[2621]: 2026-09-04T01:16:06.852438Z INFO MonitorHandler ExtHandler Network interfaces: Sep 4 01:16:06.852484 waagent[2621]: Executing ['ip', '-a', '-o', 'link']: Sep 4 01:16:06.852484 waagent[2621]: 1: lo: mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000\ link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 Sep 4 01:16:06.852484 waagent[2621]: 2: eth0: mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000\ link/ether 70:a8:a5:7f:db:30 brd ff:ff:ff:ff:ff:ff\ alias Network Device\ altname enx70a8a57fdb30 Sep 4 01:16:06.852484 waagent[2621]: 3: enP30832s1: mtu 1500 qdisc mq master eth0 state UP mode DEFAULT group default qlen 1000\ link/ether 70:a8:a5:7f:db:30 brd ff:ff:ff:ff:ff:ff\ altname enP30832p0s0 Sep 4 01:16:06.852484 waagent[2621]: Executing ['ip', '-4', '-a', '-o', 'address']: Sep 4 01:16:06.852484 waagent[2621]: 1: lo inet 127.0.0.1/8 scope host lo\ valid_lft forever preferred_lft forever Sep 4 01:16:06.852484 waagent[2621]: 2: eth0 inet 10.0.0.35/24 metric 1024 brd 10.0.0.255 scope global eth0\ valid_lft forever preferred_lft forever Sep 4 01:16:06.852484 waagent[2621]: Executing ['ip', '-6', '-a', '-o', 'address']: Sep 4 01:16:06.852484 waagent[2621]: 1: lo inet6 ::1/128 scope host noprefixroute \ valid_lft forever preferred_lft forever Sep 4 01:16:06.852484 waagent[2621]: 2: eth0 inet6 fe80::72a8:a5ff:fe7f:db30/64 scope link proto kernel_ll \ valid_lft forever preferred_lft forever Sep 4 01:16:06.882468 waagent[2621]: 2026-09-04T01:16:06.882426Z INFO EnvHandler ExtHandler Created firewall rules for the Azure Fabric: Sep 4 01:16:06.882468 waagent[2621]: Chain INPUT (policy ACCEPT 0 packets, 0 bytes) Sep 4 01:16:06.882468 waagent[2621]: pkts bytes target prot opt in out source destination Sep 4 01:16:06.882468 waagent[2621]: Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) Sep 4 01:16:06.882468 waagent[2621]: pkts bytes target prot opt in out source destination Sep 4 01:16:06.882468 waagent[2621]: Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes) Sep 4 01:16:06.882468 waagent[2621]: pkts bytes target prot opt in out source destination Sep 4 01:16:06.882468 waagent[2621]: 0 0 ACCEPT tcp -- * * 0.0.0.0/0 168.63.129.16 tcp dpt:53 Sep 4 01:16:06.882468 waagent[2621]: 9 874 ACCEPT tcp -- * * 0.0.0.0/0 168.63.129.16 owner UID match 0 Sep 4 01:16:06.882468 waagent[2621]: 0 0 DROP tcp -- * * 0.0.0.0/0 168.63.129.16 ctstate INVALID,NEW Sep 4 01:16:06.884965 waagent[2621]: 2026-09-04T01:16:06.884921Z INFO EnvHandler ExtHandler Current Firewall rules: Sep 4 01:16:06.884965 waagent[2621]: Chain INPUT (policy ACCEPT 0 packets, 0 bytes) Sep 4 01:16:06.884965 waagent[2621]: pkts bytes target prot opt in out source destination Sep 4 01:16:06.884965 waagent[2621]: Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) Sep 4 01:16:06.884965 waagent[2621]: pkts bytes target prot opt in out source destination Sep 4 01:16:06.884965 waagent[2621]: Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes) Sep 4 01:16:06.884965 waagent[2621]: pkts bytes target prot opt in out source destination Sep 4 01:16:06.884965 waagent[2621]: 0 0 ACCEPT tcp -- * * 0.0.0.0/0 168.63.129.16 tcp dpt:53 Sep 4 01:16:06.884965 waagent[2621]: 12 1408 ACCEPT tcp -- * * 0.0.0.0/0 168.63.129.16 owner UID match 0 Sep 4 01:16:06.884965 waagent[2621]: 0 0 DROP tcp -- * * 0.0.0.0/0 168.63.129.16 ctstate INVALID,NEW Sep 4 01:16:26.472369 chronyd[2400]: Selected source PHC0 Sep 4 01:16:31.830341 systemd[1]: Created slice system-sshd.slice - Slice /system/sshd. Sep 4 01:16:31.831376 systemd[1]: Started sshd@0-10.0.0.35:22-20.61.25.254:36098.service - OpenSSH per-connection server daemon (20.61.25.254:36098). Sep 4 01:16:32.115836 sshd[2769]: Accepted publickey for core from 20.61.25.254 port 36098 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:32.116938 sshd-session[2769]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:32.121259 systemd-logind[2416]: New session 4 of user core. Sep 4 01:16:32.127017 systemd[1]: Started session-4.scope - Session 4 of User core. Sep 4 01:16:32.186019 systemd[1]: Started sshd@1-10.0.0.35:22-20.61.25.254:36102.service - OpenSSH per-connection server daemon (20.61.25.254:36102). Sep 4 01:16:32.295979 sshd[2776]: Accepted publickey for core from 20.61.25.254 port 36102 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:32.297112 sshd-session[2776]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:32.301025 systemd-logind[2416]: New session 5 of user core. Sep 4 01:16:32.309002 systemd[1]: Started session-5.scope - Session 5 of User core. Sep 4 01:16:32.345639 sshd[2780]: Connection closed by 20.61.25.254 port 36102 Sep 4 01:16:32.346965 sshd-session[2776]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:32.350227 systemd-logind[2416]: Session 5 logged out. Waiting for processes to exit. Sep 4 01:16:32.350608 systemd[1]: sshd@1-10.0.0.35:22-20.61.25.254:36102.service: Deactivated successfully. Sep 4 01:16:32.352096 systemd[1]: session-5.scope: Deactivated successfully. Sep 4 01:16:32.353659 systemd-logind[2416]: Removed session 5. Sep 4 01:16:32.368144 systemd[1]: Started sshd@2-10.0.0.35:22-20.61.25.254:36108.service - OpenSSH per-connection server daemon (20.61.25.254:36108). Sep 4 01:16:32.481012 sshd[2786]: Accepted publickey for core from 20.61.25.254 port 36108 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:32.481991 sshd-session[2786]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:32.486357 systemd-logind[2416]: New session 6 of user core. Sep 4 01:16:32.496000 systemd[1]: Started session-6.scope - Session 6 of User core. Sep 4 01:16:32.529183 sshd[2790]: Connection closed by 20.61.25.254 port 36108 Sep 4 01:16:32.529594 sshd-session[2786]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:32.532287 systemd[1]: sshd@2-10.0.0.35:22-20.61.25.254:36108.service: Deactivated successfully. Sep 4 01:16:32.533575 systemd[1]: session-6.scope: Deactivated successfully. Sep 4 01:16:32.534638 systemd-logind[2416]: Session 6 logged out. Waiting for processes to exit. Sep 4 01:16:32.535736 systemd-logind[2416]: Removed session 6. Sep 4 01:16:32.553266 systemd[1]: Started sshd@3-10.0.0.35:22-20.61.25.254:36122.service - OpenSSH per-connection server daemon (20.61.25.254:36122). Sep 4 01:16:32.664935 sshd[2796]: Accepted publickey for core from 20.61.25.254 port 36122 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:32.665887 sshd-session[2796]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:32.670259 systemd-logind[2416]: New session 7 of user core. Sep 4 01:16:32.679008 systemd[1]: Started session-7.scope - Session 7 of User core. Sep 4 01:16:32.715720 sshd[2800]: Connection closed by 20.61.25.254 port 36122 Sep 4 01:16:32.716143 sshd-session[2796]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:32.719551 systemd[1]: sshd@3-10.0.0.35:22-20.61.25.254:36122.service: Deactivated successfully. Sep 4 01:16:32.720993 systemd[1]: session-7.scope: Deactivated successfully. Sep 4 01:16:32.722090 systemd-logind[2416]: Session 7 logged out. Waiting for processes to exit. Sep 4 01:16:32.723083 systemd-logind[2416]: Removed session 7. Sep 4 01:16:32.748043 systemd[1]: Started sshd@4-10.0.0.35:22-20.61.25.254:36136.service - OpenSSH per-connection server daemon (20.61.25.254:36136). Sep 4 01:16:32.858724 sshd[2806]: Accepted publickey for core from 20.61.25.254 port 36136 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:32.859793 sshd-session[2806]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:32.863501 systemd-logind[2416]: New session 8 of user core. Sep 4 01:16:32.868005 systemd[1]: Started session-8.scope - Session 8 of User core. Sep 4 01:16:33.006687 sudo[2811]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/setenforce 1 Sep 4 01:16:33.006941 sudo[2811]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:33.022494 sudo[2811]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:33.037166 sshd[2810]: Connection closed by 20.61.25.254 port 36136 Sep 4 01:16:33.038767 sshd-session[2806]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:33.042196 systemd-logind[2416]: Session 8 logged out. Waiting for processes to exit. Sep 4 01:16:33.042370 systemd[1]: sshd@4-10.0.0.35:22-20.61.25.254:36136.service: Deactivated successfully. Sep 4 01:16:33.043902 systemd[1]: session-8.scope: Deactivated successfully. Sep 4 01:16:33.045276 systemd-logind[2416]: Removed session 8. Sep 4 01:16:33.069486 systemd[1]: Started sshd@5-10.0.0.35:22-20.61.25.254:36138.service - OpenSSH per-connection server daemon (20.61.25.254:36138). Sep 4 01:16:33.184894 sshd[2818]: Accepted publickey for core from 20.61.25.254 port 36138 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:33.185946 sshd-session[2818]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:33.190375 systemd-logind[2416]: New session 9 of user core. Sep 4 01:16:33.196005 systemd[1]: Started session-9.scope - Session 9 of User core. Sep 4 01:16:33.220064 sudo[2824]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/rm -rf /etc/audit/rules.d/80-selinux.rules /etc/audit/rules.d/99-default.rules Sep 4 01:16:33.220455 sudo[2824]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:33.221744 sudo[2824]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:33.226682 sudo[2823]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/systemctl restart audit-rules Sep 4 01:16:33.226898 sudo[2823]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:33.232792 systemd[1]: Starting audit-rules.service - Load Audit Rules... Sep 4 01:16:33.291688 kernel: kauditd_printk_skb: 116 callbacks suppressed Sep 4 01:16:33.291795 kernel: audit: type=1305 audit(1788484593.285:212): auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 op=remove_rule key=(null) list=5 res=1 Sep 4 01:16:33.285000 audit: CONFIG_CHANGE auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 op=remove_rule key=(null) list=5 res=1 Sep 4 01:16:33.291956 augenrules[2848]: No rules Sep 4 01:16:33.285000 audit[2848]: SYSCALL arch=c000003e syscall=44 success=yes exit=1056 a0=3 a1=7ffda3b4a9f0 a2=420 a3=0 items=0 ppid=2829 pid=2848 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditctl" exe="/usr/bin/auditctl" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:33.294659 systemd[1]: audit-rules.service: Deactivated successfully. Sep 4 01:16:33.294859 kernel: audit: type=1300 audit(1788484593.285:212): arch=c000003e syscall=44 success=yes exit=1056 a0=3 a1=7ffda3b4a9f0 a2=420 a3=0 items=0 ppid=2829 pid=2848 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditctl" exe="/usr/bin/auditctl" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:33.294895 systemd[1]: Finished audit-rules.service - Load Audit Rules. Sep 4 01:16:33.296204 sudo[2823]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:33.285000 audit: PROCTITLE proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573 Sep 4 01:16:33.294000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.300098 kernel: audit: type=1327 audit(1788484593.285:212): proctitle=2F7362696E2F617564697463746C002D52002F6574632F61756469742F61756469742E72756C6573 Sep 4 01:16:33.300154 kernel: audit: type=1130 audit(1788484593.294:213): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.300175 kernel: audit: type=1131 audit(1788484593.294:214): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.294000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.301792 kernel: audit: type=1106 audit(1788484593.295:215): pid=2823 uid=500 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.295000 audit[2823]: USER_END pid=2823 uid=500 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.303715 kernel: audit: type=1104 audit(1788484593.295:216): pid=2823 uid=500 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.295000 audit[2823]: CRED_DISP pid=2823 uid=500 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.312184 sshd[2822]: Connection closed by 20.61.25.254 port 36138 Sep 4 01:16:33.313018 sshd-session[2818]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:33.313000 audit[2818]: USER_END pid=2818 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:33.313000 audit[2818]: CRED_DISP pid=2818 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:33.319184 systemd[1]: sshd@5-10.0.0.35:22-20.61.25.254:36138.service: Deactivated successfully. Sep 4 01:16:33.321693 systemd[1]: session-9.scope: Deactivated successfully. Sep 4 01:16:33.322576 kernel: audit: type=1106 audit(1788484593.313:217): pid=2818 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:33.322621 kernel: audit: type=1104 audit(1788484593.313:218): pid=2818 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:33.318000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@5-10.0.0.35:22-20.61.25.254:36138 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.325835 kernel: audit: type=1131 audit(1788484593.318:219): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@5-10.0.0.35:22-20.61.25.254:36138 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:33.326320 systemd-logind[2416]: Session 9 logged out. Waiting for processes to exit. Sep 4 01:16:33.327314 systemd-logind[2416]: Removed session 9. Sep 4 01:16:38.858043 systemd[1]: Started sshd@6-10.0.0.35:22-20.61.25.254:48598.service - OpenSSH per-connection server daemon (20.61.25.254:48598). Sep 4 01:16:38.857000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-10.0.0.35:22-20.61.25.254:48598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:38.864945 kernel: audit: type=1130 audit(1788484598.857:220): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-10.0.0.35:22-20.61.25.254:48598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:38.967000 audit[2857]: USER_ACCT pid=2857 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:38.970072 sshd-session[2857]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:38.973296 sshd[2857]: Accepted publickey for core from 20.61.25.254 port 48598 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:38.967000 audit[2857]: CRED_ACQ pid=2857 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:38.977309 kernel: audit: type=1101 audit(1788484598.967:221): pid=2857 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:38.977346 kernel: audit: type=1103 audit(1788484598.967:222): pid=2857 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:38.980875 kernel: audit: type=1006 audit(1788484598.967:223): pid=2857 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=10 res=1 Sep 4 01:16:38.967000 audit[2857]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fff90448a50 a2=3 a3=0 items=0 ppid=1 pid=2857 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=10 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:38.983442 systemd-logind[2416]: New session 10 of user core. Sep 4 01:16:38.986964 kernel: audit: type=1300 audit(1788484598.967:223): arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fff90448a50 a2=3 a3=0 items=0 ppid=1 pid=2857 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=10 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:38.989599 kernel: audit: type=1327 audit(1788484598.967:223): proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:38.967000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:38.990043 systemd[1]: Started session-10.scope - Session 10 of User core. Sep 4 01:16:38.991000 audit[2857]: USER_START pid=2857 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:39.001903 kernel: audit: type=1105 audit(1788484598.991:224): pid=2857 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:39.001960 kernel: audit: type=1103 audit(1788484598.997:225): pid=2861 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:38.997000 audit[2861]: CRED_ACQ pid=2861 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:39.025000 audit[2866]: USER_ACCT pid=2866 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.026506 sudo[2866]: core : PWD=/tmp/tmp.RpzNHOq4f0 ; USER=root ; COMMAND=/usr/sbin/ldd /usr/bin/nc /usr/bin/timeout Sep 4 01:16:39.027069 sudo[2866]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:39.026000 audit[2866]: CRED_REFR pid=2866 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.031576 kernel: audit: type=1101 audit(1788484599.025:226): pid=2866 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.031611 kernel: audit: type=1110 audit(1788484599.026:227): pid=2866 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.026000 audit[2866]: USER_START pid=2866 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.086325 sudo[2866]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:39.085000 audit[2866]: USER_END pid=2866 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.085000 audit[2866]: CRED_DISP pid=2866 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.091000 audit[2879]: USER_ACCT pid=2879 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.092739 sudo[2879]: core : PWD=/tmp/tmp.RpzNHOq4f0 ; USER=root ; COMMAND=/usr/sbin/rsync -av --relative --copy-links /usr/bin/nc /usr/bin/timeout /lib64/ld-linux-x86-64.so.2 /lib64/libbsd.so.0 /lib64/libc.so.6 /lib64/libmd.so.0 /lib64/libresolv.so.2 ./ Sep 4 01:16:39.092981 sudo[2879]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:39.092000 audit[2879]: CRED_REFR pid=2879 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.092000 audit[2879]: USER_START pid=2879 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.217501 sudo[2879]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:39.216000 audit[2879]: USER_END pid=2879 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.216000 audit[2879]: CRED_DISP pid=2879 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.221000 audit[2862]: USER_ACCT pid=2862 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.222987 sudo[2862]: core : PWD=/tmp/tmp.RpzNHOq4f0 ; USER=root ; COMMAND=/usr/sbin/docker build -t netcat . Sep 4 01:16:39.223206 sudo[2862]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:39.222000 audit[2862]: CRED_REFR pid=2862 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:39.222000 audit[2862]: USER_START pid=2862 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:40.223241 systemd[1]: Starting docker.service - Docker Application Container Engine... Sep 4 01:16:40.232103 (dockerd)[2892]: docker.service: Referenced but unset environment variable evaluates to an empty string: DOCKER_CGROUPS, DOCKER_OPTS, DOCKER_OPT_BIP, DOCKER_OPT_IPMASQ, DOCKER_OPT_MTU Sep 4 01:16:42.406933 dockerd[2892]: time="2026-09-04T01:16:42.406881509Z" level=info msg="Starting up" Sep 4 01:16:42.408933 dockerd[2892]: time="2026-09-04T01:16:42.408904730Z" level=info msg="OTEL tracing is not configured, using no-op tracer provider" Sep 4 01:16:42.418419 dockerd[2892]: time="2026-09-04T01:16:42.418380677Z" level=info msg="Creating a containerd client" address=/var/run/docker/libcontainerd/docker-containerd.sock timeout=1m0s Sep 4 01:16:42.518655 systemd[1]: var-lib-docker-check\x2doverlayfs\x2dsupport3733275942-merged.mount: Deactivated successfully. Sep 4 01:16:44.236627 kernel: hv_balloon: Max. dynamic memory size: 8192 MB Sep 4 01:16:45.774259 dockerd[2892]: time="2026-09-04T01:16:45.774203711Z" level=info msg="Loading containers: start." Sep 4 01:16:45.828867 kernel: Initializing XFRM netlink socket Sep 4 01:16:45.852000 audit[2955]: NETFILTER_CFG table=nat:5 family=2 entries=2 op=nft_register_chain pid=2955 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.854650 kernel: kauditd_printk_skb: 11 callbacks suppressed Sep 4 01:16:45.854744 kernel: audit: type=1325 audit(1788484605.852:239): table=nat:5 family=2 entries=2 op=nft_register_chain pid=2955 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.852000 audit[2955]: SYSCALL arch=c000003e syscall=46 success=yes exit=116 a0=3 a1=7ffe5e3f5910 a2=0 a3=0 items=0 ppid=2892 pid=2955 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.860162 kernel: audit: type=1300 audit(1788484605.852:239): arch=c000003e syscall=46 success=yes exit=116 a0=3 a1=7ffe5e3f5910 a2=0 a3=0 items=0 ppid=2892 pid=2955 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.852000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4E00444F434B4552 Sep 4 01:16:45.862362 kernel: audit: type=1327 audit(1788484605.852:239): proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4E00444F434B4552 Sep 4 01:16:45.856000 audit[2957]: NETFILTER_CFG table=filter:6 family=2 entries=2 op=nft_register_chain pid=2957 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.864729 kernel: audit: type=1325 audit(1788484605.856:240): table=filter:6 family=2 entries=2 op=nft_register_chain pid=2957 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.856000 audit[2957]: SYSCALL arch=c000003e syscall=46 success=yes exit=124 a0=3 a1=7ffd9ce35220 a2=0 a3=0 items=0 ppid=2892 pid=2957 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.868460 kernel: audit: type=1300 audit(1788484605.856:240): arch=c000003e syscall=46 success=yes exit=124 a0=3 a1=7ffd9ce35220 a2=0 a3=0 items=0 ppid=2892 pid=2957 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.856000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B4552 Sep 4 01:16:45.871749 kernel: audit: type=1327 audit(1788484605.856:240): proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B4552 Sep 4 01:16:45.873925 kernel: audit: type=1325 audit(1788484605.861:241): table=filter:7 family=2 entries=1 op=nft_register_chain pid=2959 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.861000 audit[2959]: NETFILTER_CFG table=filter:7 family=2 entries=1 op=nft_register_chain pid=2959 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.861000 audit[2959]: SYSCALL arch=c000003e syscall=46 success=yes exit=100 a0=3 a1=7ffeb3ce44e0 a2=0 a3=0 items=0 ppid=2892 pid=2959 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.878697 kernel: audit: type=1300 audit(1788484605.861:241): arch=c000003e syscall=46 success=yes exit=100 a0=3 a1=7ffeb3ce44e0 a2=0 a3=0 items=0 ppid=2892 pid=2959 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.861000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D464F5257415244 Sep 4 01:16:45.881801 kernel: audit: type=1327 audit(1788484605.861:241): proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D464F5257415244 Sep 4 01:16:45.869000 audit[2961]: NETFILTER_CFG table=filter:8 family=2 entries=1 op=nft_register_chain pid=2961 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.884036 kernel: audit: type=1325 audit(1788484605.869:242): table=filter:8 family=2 entries=1 op=nft_register_chain pid=2961 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.869000 audit[2961]: SYSCALL arch=c000003e syscall=46 success=yes exit=100 a0=3 a1=7ffdfab0e240 a2=0 a3=0 items=0 ppid=2892 pid=2961 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.869000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D425249444745 Sep 4 01:16:45.872000 audit[2963]: NETFILTER_CFG table=filter:9 family=2 entries=1 op=nft_register_chain pid=2963 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.872000 audit[2963]: SYSCALL arch=c000003e syscall=46 success=yes exit=96 a0=3 a1=7fff821af8f0 a2=0 a3=0 items=0 ppid=2892 pid=2963 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.872000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D4354 Sep 4 01:16:45.876000 audit[2965]: NETFILTER_CFG table=filter:10 family=2 entries=1 op=nft_register_chain pid=2965 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.876000 audit[2965]: SYSCALL arch=c000003e syscall=46 success=yes exit=112 a0=3 a1=7ffd6bd86840 a2=0 a3=0 items=0 ppid=2892 pid=2965 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.876000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D49534F4C4154494F4E2D53544147452D31 Sep 4 01:16:45.879000 audit[2967]: NETFILTER_CFG table=filter:11 family=2 entries=1 op=nft_register_chain pid=2967 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.879000 audit[2967]: SYSCALL arch=c000003e syscall=46 success=yes exit=112 a0=3 a1=7ffe873ffc60 a2=0 a3=0 items=0 ppid=2892 pid=2967 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.879000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D49534F4C4154494F4E2D53544147452D32 Sep 4 01:16:45.883000 audit[2969]: NETFILTER_CFG table=nat:12 family=2 entries=2 op=nft_register_chain pid=2969 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.883000 audit[2969]: SYSCALL arch=c000003e syscall=46 success=yes exit=384 a0=3 a1=7ffe57eb4af0 a2=0 a3=0 items=0 ppid=2892 pid=2969 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.883000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4100505245524F5554494E47002D6D006164647274797065002D2D6473742D74797065004C4F43414C002D6A00444F434B4552 Sep 4 01:16:45.977000 audit[2972]: NETFILTER_CFG table=nat:13 family=2 entries=2 op=nft_register_chain pid=2972 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.977000 audit[2972]: SYSCALL arch=c000003e syscall=46 success=yes exit=472 a0=3 a1=7ffd7d4ebd40 a2=0 a3=0 items=0 ppid=2892 pid=2972 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.977000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D41004F5554505554002D6D006164647274797065002D2D6473742D74797065004C4F43414C002D6A00444F434B45520000002D2D647374003132372E302E302E302F38 Sep 4 01:16:45.979000 audit[2974]: NETFILTER_CFG table=filter:14 family=2 entries=2 op=nft_register_chain pid=2974 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.979000 audit[2974]: SYSCALL arch=c000003e syscall=46 success=yes exit=340 a0=3 a1=7fff85adfe20 a2=0 a3=0 items=0 ppid=2892 pid=2974 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.979000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D4900464F5257415244002D6A00444F434B45522D464F5257415244 Sep 4 01:16:45.981000 audit[2976]: NETFILTER_CFG table=filter:15 family=2 entries=1 op=nft_register_rule pid=2976 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.981000 audit[2976]: SYSCALL arch=c000003e syscall=46 success=yes exit=236 a0=3 a1=7ffd36e37920 a2=0 a3=0 items=0 ppid=2892 pid=2976 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.981000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D4900444F434B45522D464F5257415244002D6A00444F434B45522D425249444745 Sep 4 01:16:45.983000 audit[2978]: NETFILTER_CFG table=filter:16 family=2 entries=1 op=nft_register_rule pid=2978 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.983000 audit[2978]: SYSCALL arch=c000003e syscall=46 success=yes exit=248 a0=3 a1=7fffb3cbc6c0 a2=0 a3=0 items=0 ppid=2892 pid=2978 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.983000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D4900444F434B45522D464F5257415244002D6A00444F434B45522D49534F4C4154494F4E2D53544147452D31 Sep 4 01:16:45.984000 audit[2980]: NETFILTER_CFG table=filter:17 family=2 entries=1 op=nft_register_rule pid=2980 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:45.984000 audit[2980]: SYSCALL arch=c000003e syscall=46 success=yes exit=232 a0=3 a1=7ffd78497de0 a2=0 a3=0 items=0 ppid=2892 pid=2980 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:45.984000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D4900444F434B45522D464F5257415244002D6A00444F434B45522D4354 Sep 4 01:16:46.065000 audit[3010]: NETFILTER_CFG table=nat:18 family=10 entries=2 op=nft_register_chain pid=3010 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.065000 audit[3010]: SYSCALL arch=c000003e syscall=46 success=yes exit=116 a0=3 a1=7fff720e0e90 a2=0 a3=0 items=0 ppid=2892 pid=3010 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.065000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D74006E6174002D4E00444F434B4552 Sep 4 01:16:46.067000 audit[3012]: NETFILTER_CFG table=filter:19 family=10 entries=2 op=nft_register_chain pid=3012 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.067000 audit[3012]: SYSCALL arch=c000003e syscall=46 success=yes exit=124 a0=3 a1=7fff8428fb10 a2=0 a3=0 items=0 ppid=2892 pid=3012 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.067000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B4552 Sep 4 01:16:46.069000 audit[3014]: NETFILTER_CFG table=filter:20 family=10 entries=1 op=nft_register_chain pid=3014 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.069000 audit[3014]: SYSCALL arch=c000003e syscall=46 success=yes exit=100 a0=3 a1=7ffca51fa550 a2=0 a3=0 items=0 ppid=2892 pid=3014 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.069000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D464F5257415244 Sep 4 01:16:46.070000 audit[3016]: NETFILTER_CFG table=filter:21 family=10 entries=1 op=nft_register_chain pid=3016 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.070000 audit[3016]: SYSCALL arch=c000003e syscall=46 success=yes exit=100 a0=3 a1=7ffc845b7970 a2=0 a3=0 items=0 ppid=2892 pid=3016 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.070000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D425249444745 Sep 4 01:16:46.072000 audit[3018]: NETFILTER_CFG table=filter:22 family=10 entries=1 op=nft_register_chain pid=3018 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.072000 audit[3018]: SYSCALL arch=c000003e syscall=46 success=yes exit=96 a0=3 a1=7ffc0200dbc0 a2=0 a3=0 items=0 ppid=2892 pid=3018 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.072000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D4354 Sep 4 01:16:46.073000 audit[3020]: NETFILTER_CFG table=filter:23 family=10 entries=1 op=nft_register_chain pid=3020 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.073000 audit[3020]: SYSCALL arch=c000003e syscall=46 success=yes exit=112 a0=3 a1=7fff3724c2d0 a2=0 a3=0 items=0 ppid=2892 pid=3020 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.073000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D49534F4C4154494F4E2D53544147452D31 Sep 4 01:16:46.075000 audit[3022]: NETFILTER_CFG table=filter:24 family=10 entries=1 op=nft_register_chain pid=3022 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.075000 audit[3022]: SYSCALL arch=c000003e syscall=46 success=yes exit=112 a0=3 a1=7ffd4e86bdd0 a2=0 a3=0 items=0 ppid=2892 pid=3022 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.075000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D49534F4C4154494F4E2D53544147452D32 Sep 4 01:16:46.076000 audit[3024]: NETFILTER_CFG table=nat:25 family=10 entries=2 op=nft_register_chain pid=3024 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.076000 audit[3024]: SYSCALL arch=c000003e syscall=46 success=yes exit=384 a0=3 a1=7fff628a5dd0 a2=0 a3=0 items=0 ppid=2892 pid=3024 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.076000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D74006E6174002D4100505245524F5554494E47002D6D006164647274797065002D2D6473742D74797065004C4F43414C002D6A00444F434B4552 Sep 4 01:16:46.078000 audit[3026]: NETFILTER_CFG table=nat:26 family=10 entries=2 op=nft_register_chain pid=3026 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.078000 audit[3026]: SYSCALL arch=c000003e syscall=46 success=yes exit=484 a0=3 a1=7ffd993debc0 a2=0 a3=0 items=0 ppid=2892 pid=3026 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.078000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D74006E6174002D41004F5554505554002D6D006164647274797065002D2D6473742D74797065004C4F43414C002D6A00444F434B45520000002D2D647374003A3A312F313238 Sep 4 01:16:46.080000 audit[3028]: NETFILTER_CFG table=filter:27 family=10 entries=2 op=nft_register_chain pid=3028 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.080000 audit[3028]: SYSCALL arch=c000003e syscall=46 success=yes exit=340 a0=3 a1=7ffd21da36a0 a2=0 a3=0 items=0 ppid=2892 pid=3028 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.080000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D4900464F5257415244002D6A00444F434B45522D464F5257415244 Sep 4 01:16:46.082000 audit[3030]: NETFILTER_CFG table=filter:28 family=10 entries=1 op=nft_register_rule pid=3030 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.082000 audit[3030]: SYSCALL arch=c000003e syscall=46 success=yes exit=236 a0=3 a1=7ffd3c1225e0 a2=0 a3=0 items=0 ppid=2892 pid=3030 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.082000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D4900444F434B45522D464F5257415244002D6A00444F434B45522D425249444745 Sep 4 01:16:46.083000 audit[3032]: NETFILTER_CFG table=filter:29 family=10 entries=1 op=nft_register_rule pid=3032 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.083000 audit[3032]: SYSCALL arch=c000003e syscall=46 success=yes exit=248 a0=3 a1=7ffed3eec840 a2=0 a3=0 items=0 ppid=2892 pid=3032 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.083000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D4900444F434B45522D464F5257415244002D6A00444F434B45522D49534F4C4154494F4E2D53544147452D31 Sep 4 01:16:46.085000 audit[3034]: NETFILTER_CFG table=filter:30 family=10 entries=1 op=nft_register_rule pid=3034 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.085000 audit[3034]: SYSCALL arch=c000003e syscall=46 success=yes exit=232 a0=3 a1=7fff712fa6f0 a2=0 a3=0 items=0 ppid=2892 pid=3034 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.085000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D4900444F434B45522D464F5257415244002D6A00444F434B45522D4354 Sep 4 01:16:46.089000 audit[3039]: NETFILTER_CFG table=filter:31 family=2 entries=1 op=nft_register_chain pid=3039 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.089000 audit[3039]: SYSCALL arch=c000003e syscall=46 success=yes exit=96 a0=3 a1=7ffd504d2b20 a2=0 a3=0 items=0 ppid=2892 pid=3039 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.089000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D55534552 Sep 4 01:16:46.090000 audit[3041]: NETFILTER_CFG table=filter:32 family=2 entries=1 op=nft_register_rule pid=3041 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.090000 audit[3041]: SYSCALL arch=c000003e syscall=46 success=yes exit=212 a0=3 a1=7fffa5376fe0 a2=0 a3=0 items=0 ppid=2892 pid=3041 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.090000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D4100444F434B45522D55534552002D6A0052455455524E Sep 4 01:16:46.092000 audit[3043]: NETFILTER_CFG table=filter:33 family=2 entries=1 op=nft_register_rule pid=3043 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.092000 audit[3043]: SYSCALL arch=c000003e syscall=46 success=yes exit=224 a0=3 a1=7ffeb61008e0 a2=0 a3=0 items=0 ppid=2892 pid=3043 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.092000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D4900464F5257415244002D6A00444F434B45522D55534552 Sep 4 01:16:46.093000 audit[3045]: NETFILTER_CFG table=filter:34 family=10 entries=1 op=nft_register_chain pid=3045 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.093000 audit[3045]: SYSCALL arch=c000003e syscall=46 success=yes exit=96 a0=3 a1=7fff81a6a6a0 a2=0 a3=0 items=0 ppid=2892 pid=3045 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.093000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D740066696C746572002D4E00444F434B45522D55534552 Sep 4 01:16:46.095000 audit[3047]: NETFILTER_CFG table=filter:35 family=10 entries=1 op=nft_register_rule pid=3047 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.095000 audit[3047]: SYSCALL arch=c000003e syscall=46 success=yes exit=212 a0=3 a1=7ffe0122a780 a2=0 a3=0 items=0 ppid=2892 pid=3047 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.095000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D4100444F434B45522D55534552002D6A0052455455524E Sep 4 01:16:46.096000 audit[3049]: NETFILTER_CFG table=filter:36 family=10 entries=1 op=nft_register_rule pid=3049 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" Sep 4 01:16:46.096000 audit[3049]: SYSCALL arch=c000003e syscall=46 success=yes exit=224 a0=3 a1=7ffd306d9190 a2=0 a3=0 items=0 ppid=2892 pid=3049 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.096000 audit: PROCTITLE proctitle=2F7573722F62696E2F6970367461626C6573002D2D77616974002D4900464F5257415244002D6A00444F434B45522D55534552 Sep 4 01:16:46.233000 audit[3054]: NETFILTER_CFG table=nat:37 family=2 entries=2 op=nft_register_chain pid=3054 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.233000 audit[3054]: SYSCALL arch=c000003e syscall=46 success=yes exit=520 a0=3 a1=7ffc6048d440 a2=0 a3=0 items=0 ppid=2892 pid=3054 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.233000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4900504F5354524F5554494E47002D73003137322E31372E302E302F31360000002D6F00646F636B657230002D6A004D415351554552414445 Sep 4 01:16:46.235000 audit[3056]: NETFILTER_CFG table=nat:38 family=2 entries=1 op=nft_register_rule pid=3056 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.235000 audit[3056]: SYSCALL arch=c000003e syscall=46 success=yes exit=288 a0=3 a1=7ffde9337580 a2=0 a3=0 items=0 ppid=2892 pid=3056 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.235000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4900444F434B4552002D6900646F636B657230002D6A0052455455524E Sep 4 01:16:46.242000 audit[3064]: NETFILTER_CFG table=filter:39 family=2 entries=1 op=nft_register_rule pid=3064 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.242000 audit[3064]: SYSCALL arch=c000003e syscall=46 success=yes exit=300 a0=3 a1=7ffdb90f73f0 a2=0 a3=0 items=0 ppid=2892 pid=3064 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.242000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45522D464F5257415244002D6900646F636B657230002D6A00414343455054 Sep 4 01:16:46.246000 audit[3069]: NETFILTER_CFG table=filter:40 family=2 entries=1 op=nft_register_rule pid=3069 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.246000 audit[3069]: SYSCALL arch=c000003e syscall=46 success=yes exit=376 a0=3 a1=7ffe408201c0 a2=0 a3=0 items=0 ppid=2892 pid=3069 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.246000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45520000002D6900646F636B657230002D6F00646F636B657230002D6A0044524F50 Sep 4 01:16:46.248000 audit[3071]: NETFILTER_CFG table=filter:41 family=2 entries=1 op=nft_register_rule pid=3071 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.248000 audit[3071]: SYSCALL arch=c000003e syscall=46 success=yes exit=512 a0=3 a1=7fff514e5980 a2=0 a3=0 items=0 ppid=2892 pid=3071 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.248000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45522D4354002D6F00646F636B657230002D6D00636F6E6E747261636B002D2D637473746174650052454C415445442C45535441424C4953484544002D6A00414343455054 Sep 4 01:16:46.250000 audit[3073]: NETFILTER_CFG table=filter:42 family=2 entries=1 op=nft_register_rule pid=3073 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.250000 audit[3073]: SYSCALL arch=c000003e syscall=46 success=yes exit=312 a0=3 a1=7ffcaddfd090 a2=0 a3=0 items=0 ppid=2892 pid=3073 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.250000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45522D425249444745002D6F00646F636B657230002D6A00444F434B4552 Sep 4 01:16:46.251000 audit[3075]: NETFILTER_CFG table=filter:43 family=2 entries=1 op=nft_register_rule pid=3075 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.251000 audit[3075]: SYSCALL arch=c000003e syscall=46 success=yes exit=428 a0=3 a1=7ffcb64b7d80 a2=0 a3=0 items=0 ppid=2892 pid=3075 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.251000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4100444F434B45522D49534F4C4154494F4E2D53544147452D31002D6900646F636B6572300000002D6F00646F636B657230002D6A00444F434B45522D49534F4C4154494F4E2D53544147452D32 Sep 4 01:16:46.253000 audit[3077]: NETFILTER_CFG table=filter:44 family=2 entries=1 op=nft_register_rule pid=3077 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:16:46.253000 audit[3077]: SYSCALL arch=c000003e syscall=46 success=yes exit=312 a0=3 a1=7ffffb210970 a2=0 a3=0 items=0 ppid=2892 pid=3077 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:46.253000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4900444F434B45522D49534F4C4154494F4E2D53544147452D32002D6F00646F636B657230002D6A0044524F50 Sep 4 01:16:46.254986 systemd-networkd[2174]: docker0: Link UP Sep 4 01:16:46.300990 dockerd[2892]: time="2026-09-04T01:16:46.300940681Z" level=info msg="Loading containers: done." Sep 4 01:16:46.312958 systemd[1]: var-lib-docker-overlay2-opaque\x2dbug\x2dcheck1516392037-merged.mount: Deactivated successfully. Sep 4 01:16:47.783013 update_engine[2419]: I20260904 01:16:47.782923 2419 update_attempter.cc:509] Updating boot flags... Sep 4 01:16:48.813297 dockerd[2892]: time="2026-09-04T01:16:48.813245844Z" level=warning msg="Not using native diff for overlay2, this may cause degraded performance for building images: kernel has CONFIG_OVERLAY_FS_REDIRECT_DIR enabled" storage-driver=overlay2 Sep 4 01:16:48.813725 dockerd[2892]: time="2026-09-04T01:16:48.813347414Z" level=info msg="Docker daemon" commit=6430e49a55babd9b8f4d08e70ecb2b68900770fe containerd-snapshotter=false storage-driver=overlay2 version=28.0.4 Sep 4 01:16:48.813725 dockerd[2892]: time="2026-09-04T01:16:48.813451219Z" level=info msg="Initializing buildkit" Sep 4 01:16:49.008600 dockerd[2892]: time="2026-09-04T01:16:49.008550256Z" level=info msg="Completed buildkit initialization" Sep 4 01:16:49.014764 dockerd[2892]: time="2026-09-04T01:16:49.014726837Z" level=info msg="Daemon has completed initialization" Sep 4 01:16:49.015330 dockerd[2892]: time="2026-09-04T01:16:49.014886687Z" level=info msg="API listen on /run/docker.sock" Sep 4 01:16:49.015041 systemd[1]: Started docker.service - Docker Application Container Engine. Sep 4 01:16:49.013000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=docker comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:50.813869 systemd[1]: var-lib-docker-tmp-buildkit\x2dmount1028796746.mount: Deactivated successfully. Sep 4 01:16:52.368295 sudo[2862]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:52.370109 kernel: kauditd_printk_skb: 111 callbacks suppressed Sep 4 01:16:52.370154 kernel: audit: type=1106 audit(1788484612.367:280): pid=2862 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.367000 audit[2862]: USER_END pid=2862 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.367000 audit[2862]: CRED_DISP pid=2862 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.376641 kernel: audit: type=1104 audit(1788484612.367:281): pid=2862 uid=500 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.383403 sshd[2861]: Connection closed by 20.61.25.254 port 48598 Sep 4 01:16:52.383972 sshd-session[2857]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:52.384000 audit[2857]: USER_END pid=2857 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.388646 systemd[1]: sshd@6-10.0.0.35:22-20.61.25.254:48598.service: Deactivated successfully. Sep 4 01:16:52.390445 systemd[1]: session-10.scope: Deactivated successfully. Sep 4 01:16:52.390647 systemd[1]: session-10.scope: Consumed 313ms CPU time, 130.1M memory peak. Sep 4 01:16:52.393302 systemd-logind[2416]: Session 10 logged out. Waiting for processes to exit. Sep 4 01:16:52.384000 audit[2857]: CRED_DISP pid=2857 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.394462 systemd-logind[2416]: Removed session 10. Sep 4 01:16:52.397720 kernel: audit: type=1106 audit(1788484612.384:282): pid=2857 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.397778 kernel: audit: type=1104 audit(1788484612.384:283): pid=2857 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.384000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-10.0.0.35:22-20.61.25.254:48598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.402444 kernel: audit: type=1131 audit(1788484612.384:284): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-10.0.0.35:22-20.61.25.254:48598 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.411747 systemd[1]: Started sshd@7-10.0.0.35:22-20.61.25.254:54118.service - OpenSSH per-connection server daemon (20.61.25.254:54118). Sep 4 01:16:52.411000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-10.0.0.35:22-20.61.25.254:54118 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.418463 systemd[1]: Started sshd@8-10.0.0.35:22-20.61.25.254:54122.service - OpenSSH per-connection server daemon (20.61.25.254:54122). Sep 4 01:16:52.418854 kernel: audit: type=1130 audit(1788484612.411:285): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-10.0.0.35:22-20.61.25.254:54118 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.418894 kernel: audit: type=1130 audit(1788484612.417:286): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-10.0.0.35:22-20.61.25.254:54122 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.417000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-10.0.0.35:22-20.61.25.254:54122 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.538000 audit[3154]: USER_ACCT pid=3154 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.539994 sshd[3154]: Accepted publickey for core from 20.61.25.254 port 54122 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:52.541359 sshd-session[3154]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:52.547720 kernel: audit: type=1101 audit(1788484612.538:287): pid=3154 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.547783 sshd[3153]: Accepted publickey for core from 20.61.25.254 port 54118 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:52.546820 systemd-logind[2416]: New session 11 of user core. Sep 4 01:16:52.548038 sshd-session[3153]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:52.538000 audit[3154]: CRED_ACQ pid=3154 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.552039 systemd[1]: Started session-11.scope - Session 11 of User core. Sep 4 01:16:52.556308 kernel: audit: type=1103 audit(1788484612.538:288): pid=3154 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.556360 kernel: audit: type=1006 audit(1788484612.538:289): pid=3154 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=11 res=1 Sep 4 01:16:52.538000 audit[3154]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffeb279da40 a2=3 a3=0 items=0 ppid=1 pid=3154 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=11 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:52.538000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:52.545000 audit[3153]: USER_ACCT pid=3153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.546000 audit[3153]: CRED_ACQ pid=3153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.546000 audit[3153]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe09054a30 a2=3 a3=0 items=0 ppid=1 pid=3153 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=12 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:52.546000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:52.556000 audit[3154]: USER_START pid=3154 uid=0 auid=500 ses=11 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.561355 systemd-logind[2416]: New session 12 of user core. Sep 4 01:16:52.566004 systemd[1]: Started session-12.scope - Session 12 of User core. Sep 4 01:16:52.565000 audit[3162]: CRED_ACQ pid=3162 uid=0 auid=500 ses=11 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.567000 audit[3153]: USER_START pid=3153 uid=0 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.569000 audit[3163]: CRED_ACQ pid=3163 uid=0 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.593499 sudo[3170]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:52.592000 audit[3170]: USER_ACCT pid=3170 uid=500 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.592000 audit[3170]: CRED_REFR pid=3170 uid=500 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.592000 audit[3170]: USER_START pid=3170 uid=500 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.593757 sudo[3170]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:52.692578 sudo[3170]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:52.691000 audit[3170]: USER_END pid=3170 uid=500 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.691000 audit[3170]: CRED_DISP pid=3170 uid=500 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.710662 sshd[3163]: Connection closed by 20.61.25.254 port 54118 Sep 4 01:16:52.711083 sshd-session[3153]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:52.713116 systemd[1]: var-lib-docker-overlay2-1e560a6efe3397013d8fc8429a35015ba7de9a038a054df35574429b3f363ca8\x2dinit-merged.mount: Deactivated successfully. Sep 4 01:16:52.713000 audit[3153]: USER_END pid=3153 uid=0 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.713000 audit[3153]: CRED_DISP pid=3153 uid=0 auid=500 ses=12 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.716546 systemd-logind[2416]: Session 12 logged out. Waiting for processes to exit. Sep 4 01:16:52.716753 systemd[1]: sshd@7-10.0.0.35:22-20.61.25.254:54118.service: Deactivated successfully. Sep 4 01:16:52.716000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-10.0.0.35:22-20.61.25.254:54118 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.718371 systemd[1]: session-12.scope: Deactivated successfully. Sep 4 01:16:52.719658 systemd-logind[2416]: Removed session 12. Sep 4 01:16:52.833000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@9-10.0.0.35:22-20.61.25.254:54132 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.834529 systemd[1]: Started sshd@9-10.0.0.35:22-20.61.25.254:54132.service - OpenSSH per-connection server daemon (20.61.25.254:54132). Sep 4 01:16:52.943000 audit[3182]: USER_ACCT pid=3182 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.944901 sshd[3182]: Accepted publickey for core from 20.61.25.254 port 54132 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:52.944000 audit[3182]: CRED_ACQ pid=3182 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.944000 audit[3182]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fffed994380 a2=3 a3=0 items=0 ppid=1 pid=3182 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=13 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:52.944000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:52.945835 sshd-session[3182]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:52.950134 systemd-logind[2416]: New session 13 of user core. Sep 4 01:16:52.956023 systemd[1]: Started session-13.scope - Session 13 of User core. Sep 4 01:16:52.957000 audit[3182]: USER_START pid=3182 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.958000 audit[3186]: CRED_ACQ pid=3186 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:52.978000 audit[3188]: USER_ACCT pid=3188 uid=500 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.979723 sudo[3188]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:52.979000 audit[3188]: CRED_REFR pid=3188 uid=500 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:52.980174 sudo[3188]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:52.979000 audit[3188]: USER_START pid=3188 uid=500 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.002896 sudo[3188]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:53.002000 audit[3188]: USER_END pid=3188 uid=500 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.002000 audit[3188]: CRED_DISP pid=3188 uid=500 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.017672 sshd[3186]: Connection closed by 20.61.25.254 port 54132 Sep 4 01:16:53.019162 sshd-session[3182]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:53.019000 audit[3182]: USER_END pid=3182 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.019000 audit[3182]: CRED_DISP pid=3182 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.021549 systemd[1]: sshd@9-10.0.0.35:22-20.61.25.254:54132.service: Deactivated successfully. Sep 4 01:16:53.020000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@9-10.0.0.35:22-20.61.25.254:54132 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.023119 systemd[1]: session-13.scope: Deactivated successfully. Sep 4 01:16:53.024576 systemd-logind[2416]: Session 13 logged out. Waiting for processes to exit. Sep 4 01:16:53.025241 systemd-logind[2416]: Removed session 13. Sep 4 01:16:53.145333 systemd[1]: Started sshd@10-10.0.0.35:22-20.61.25.254:54136.service - OpenSSH per-connection server daemon (20.61.25.254:54136). Sep 4 01:16:53.144000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@10-10.0.0.35:22-20.61.25.254:54136 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.253000 audit[3196]: USER_ACCT pid=3196 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.254406 sshd[3196]: Accepted publickey for core from 20.61.25.254 port 54136 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:53.254000 audit[3196]: CRED_ACQ pid=3196 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.254000 audit[3196]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fff7e916f60 a2=3 a3=0 items=0 ppid=1 pid=3196 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=14 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:53.254000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:53.255856 sshd-session[3196]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:53.260194 systemd-logind[2416]: New session 14 of user core. Sep 4 01:16:53.266016 systemd[1]: Started session-14.scope - Session 14 of User core. Sep 4 01:16:53.267000 audit[3196]: USER_START pid=3196 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.268000 audit[3200]: CRED_ACQ pid=3200 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.288000 audit[3202]: USER_ACCT pid=3202 uid=500 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.289699 sudo[3202]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:53.289000 audit[3202]: CRED_REFR pid=3202 uid=500 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.290127 sudo[3202]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:53.289000 audit[3202]: USER_START pid=3202 uid=500 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.306834 sudo[3202]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:53.306000 audit[3202]: USER_END pid=3202 uid=500 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.306000 audit[3202]: CRED_DISP pid=3202 uid=500 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.321432 sshd[3200]: Connection closed by 20.61.25.254 port 54136 Sep 4 01:16:53.321763 sshd-session[3196]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:53.321000 audit[3196]: USER_END pid=3196 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.322000 audit[3196]: CRED_DISP pid=3196 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.324892 systemd[1]: sshd@10-10.0.0.35:22-20.61.25.254:54136.service: Deactivated successfully. Sep 4 01:16:53.324000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@10-10.0.0.35:22-20.61.25.254:54136 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.326279 systemd[1]: session-14.scope: Deactivated successfully. Sep 4 01:16:53.327423 systemd-logind[2416]: Session 14 logged out. Waiting for processes to exit. Sep 4 01:16:53.328195 systemd-logind[2416]: Removed session 14. Sep 4 01:16:53.448525 systemd[1]: Started sshd@11-10.0.0.35:22-20.61.25.254:54138.service - OpenSSH per-connection server daemon (20.61.25.254:54138). Sep 4 01:16:53.448000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@11-10.0.0.35:22-20.61.25.254:54138 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.557000 audit[3210]: USER_ACCT pid=3210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.558787 sshd[3210]: Accepted publickey for core from 20.61.25.254 port 54138 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:53.558000 audit[3210]: CRED_ACQ pid=3210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.558000 audit[3210]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffedc2a0ea0 a2=3 a3=0 items=0 ppid=1 pid=3210 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:53.558000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:53.560163 sshd-session[3210]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:53.563893 systemd-logind[2416]: New session 15 of user core. Sep 4 01:16:53.573030 systemd[1]: Started session-15.scope - Session 15 of User core. Sep 4 01:16:53.574000 audit[3210]: USER_START pid=3210 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.575000 audit[3214]: CRED_ACQ pid=3214 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.596000 audit[3216]: USER_ACCT pid=3216 uid=500 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.597079 sudo[3216]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:53.596000 audit[3216]: CRED_REFR pid=3216 uid=500 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.596000 audit[3216]: USER_START pid=3216 uid=500 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.597310 sudo[3216]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:53.620356 sudo[3216]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:53.619000 audit[3216]: USER_END pid=3216 uid=500 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.619000 audit[3216]: CRED_DISP pid=3216 uid=500 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.635229 sshd[3214]: Connection closed by 20.61.25.254 port 54138 Sep 4 01:16:53.635616 sshd-session[3210]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:53.635000 audit[3210]: USER_END pid=3210 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.635000 audit[3210]: CRED_DISP pid=3210 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.638448 systemd[1]: sshd@11-10.0.0.35:22-20.61.25.254:54138.service: Deactivated successfully. Sep 4 01:16:53.637000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@11-10.0.0.35:22-20.61.25.254:54138 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.640266 systemd[1]: session-15.scope: Deactivated successfully. Sep 4 01:16:53.640993 systemd-logind[2416]: Session 15 logged out. Waiting for processes to exit. Sep 4 01:16:53.642131 systemd-logind[2416]: Removed session 15. Sep 4 01:16:53.760708 systemd[1]: Started sshd@12-10.0.0.35:22-20.61.25.254:54154.service - OpenSSH per-connection server daemon (20.61.25.254:54154). Sep 4 01:16:53.760000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@12-10.0.0.35:22-20.61.25.254:54154 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.874000 audit[3224]: USER_ACCT pid=3224 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.875889 sshd[3224]: Accepted publickey for core from 20.61.25.254 port 54154 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:53.875000 audit[3224]: CRED_ACQ pid=3224 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.875000 audit[3224]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffc250eaa00 a2=3 a3=0 items=0 ppid=1 pid=3224 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=16 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:53.875000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:53.893000 audit[3224]: USER_START pid=3224 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.894000 audit[3228]: CRED_ACQ pid=3228 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.915000 audit[3230]: USER_ACCT pid=3230 uid=500 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.915000 audit[3230]: CRED_REFR pid=3230 uid=500 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.915000 audit[3230]: USER_START pid=3230 uid=500 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.931000 audit[3230]: USER_END pid=3230 uid=500 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.931000 audit[3230]: CRED_DISP pid=3230 uid=500 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.947000 audit[3224]: USER_END pid=3224 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.948000 audit[3224]: CRED_DISP pid=3224 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:53.950000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@12-10.0.0.35:22-20.61.25.254:54154 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.073000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@13-10.0.0.35:22-20.61.25.254:54168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.186000 audit[3238]: USER_ACCT pid=3238 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.187000 audit[3238]: CRED_ACQ pid=3238 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.187000 audit[3238]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fff06e11c50 a2=3 a3=0 items=0 ppid=1 pid=3238 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=17 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:54.187000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:54.200000 audit[3238]: USER_START pid=3238 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.201000 audit[3242]: CRED_ACQ pid=3242 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.221000 audit[3244]: USER_ACCT pid=3244 uid=500 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.222000 audit[3244]: CRED_REFR pid=3244 uid=500 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.222000 audit[3244]: USER_START pid=3244 uid=500 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.237000 audit[3244]: USER_END pid=3244 uid=500 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.237000 audit[3244]: CRED_DISP pid=3244 uid=500 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.253000 audit[3238]: USER_END pid=3238 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.254000 audit[3238]: CRED_DISP pid=3238 uid=0 auid=500 ses=17 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.255000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@13-10.0.0.35:22-20.61.25.254:54168 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.377000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@14-10.0.0.35:22-20.61.25.254:54174 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.487000 audit[3251]: USER_ACCT pid=3251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.487000 audit[3251]: CRED_ACQ pid=3251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.487000 audit[3251]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fff783366c0 a2=3 a3=0 items=0 ppid=1 pid=3251 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=18 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:54.487000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:54.499000 audit[3251]: USER_START pid=3251 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.500000 audit[3255]: CRED_ACQ pid=3255 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.521000 audit[3257]: USER_ACCT pid=3257 uid=500 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.521000 audit[3257]: CRED_REFR pid=3257 uid=500 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.521000 audit[3257]: USER_START pid=3257 uid=500 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.539000 audit[3257]: USER_END pid=3257 uid=500 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.539000 audit[3257]: CRED_DISP pid=3257 uid=500 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.555000 audit[3251]: USER_END pid=3251 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.555000 audit[3251]: CRED_DISP pid=3251 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.557000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@14-10.0.0.35:22-20.61.25.254:54174 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.684000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@15-10.0.0.35:22-20.61.25.254:54188 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:53.876732 sshd-session[3224]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:54.755265 sshd[3228]: Connection closed by 20.61.25.254 port 54154 Sep 4 01:16:53.880817 systemd-logind[2416]: New session 16 of user core. Sep 4 01:16:53.916068 sudo[3230]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:54.796000 audit[3264]: USER_ACCT pid=3264 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.797000 audit[3264]: CRED_ACQ pid=3264 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.797000 audit[3264]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe68263d20 a2=3 a3=0 items=0 ppid=1 pid=3264 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=19 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:54.797000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:54.801929 sshd[3238]: Accepted publickey for core from 20.61.25.254 port 54168 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:53.891999 systemd[1]: Started session-16.scope - Session 16 of User core. Sep 4 01:16:53.916258 sudo[3230]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:54.802339 sshd[3242]: Connection closed by 20.61.25.254 port 54168 Sep 4 01:16:54.802403 sshd[3251]: Accepted publickey for core from 20.61.25.254 port 54174 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:53.950662 systemd[1]: sshd@12-10.0.0.35:22-20.61.25.254:54154.service: Deactivated successfully. Sep 4 01:16:53.932103 sudo[3230]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:54.802621 sshd[3255]: Connection closed by 20.61.25.254 port 54174 Sep 4 01:16:54.802676 sshd[3264]: Accepted publickey for core from 20.61.25.254 port 54188 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:53.952131 systemd[1]: session-16.scope: Deactivated successfully. Sep 4 01:16:53.947083 sshd-session[3224]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:53.952749 systemd-logind[2416]: Session 16 logged out. Waiting for processes to exit. Sep 4 01:16:54.188925 sshd-session[3238]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:53.953765 systemd-logind[2416]: Removed session 16. Sep 4 01:16:54.222950 sudo[3244]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:54.073902 systemd[1]: Started sshd@13-10.0.0.35:22-20.61.25.254:54168.service - OpenSSH per-connection server daemon (20.61.25.254:54168). Sep 4 01:16:54.223114 sudo[3244]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:54.193519 systemd-logind[2416]: New session 17 of user core. Sep 4 01:16:54.238221 sudo[3244]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:54.199002 systemd[1]: Started session-17.scope - Session 17 of User core. Sep 4 01:16:54.253132 sshd-session[3238]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:54.256255 systemd[1]: sshd@13-10.0.0.35:22-20.61.25.254:54168.service: Deactivated successfully. Sep 4 01:16:54.489149 sshd-session[3251]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:54.257679 systemd[1]: session-17.scope: Deactivated successfully. Sep 4 01:16:54.522500 sudo[3257]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:54.258876 systemd-logind[2416]: Session 17 logged out. Waiting for processes to exit. Sep 4 01:16:54.522695 sudo[3257]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:54.259403 systemd-logind[2416]: Removed session 17. Sep 4 01:16:54.540476 sudo[3257]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:54.378374 systemd[1]: Started sshd@14-10.0.0.35:22-20.61.25.254:54174.service - OpenSSH per-connection server daemon (20.61.25.254:54174). Sep 4 01:16:54.555500 sshd-session[3251]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:54.493341 systemd-logind[2416]: New session 18 of user core. Sep 4 01:16:54.798873 sshd-session[3264]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:54.498003 systemd[1]: Started session-18.scope - Session 18 of User core. Sep 4 01:16:54.558084 systemd[1]: sshd@14-10.0.0.35:22-20.61.25.254:54174.service: Deactivated successfully. Sep 4 01:16:54.559493 systemd[1]: session-18.scope: Deactivated successfully. Sep 4 01:16:54.560782 systemd-logind[2416]: Session 18 logged out. Waiting for processes to exit. Sep 4 01:16:54.561403 systemd-logind[2416]: Removed session 18. Sep 4 01:16:54.685285 systemd[1]: Started sshd@15-10.0.0.35:22-20.61.25.254:54188.service - OpenSSH per-connection server daemon (20.61.25.254:54188). Sep 4 01:16:54.804035 systemd-logind[2416]: New session 19 of user core. Sep 4 01:16:54.808073 systemd[1]: Started session-19.scope - Session 19 of User core. Sep 4 01:16:54.809000 audit[3264]: USER_START pid=3264 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.810000 audit[3270]: CRED_ACQ pid=3270 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.831000 audit[3272]: USER_ACCT pid=3272 uid=500 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.832298 sudo[3272]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:54.831000 audit[3272]: CRED_REFR pid=3272 uid=500 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.831000 audit[3272]: USER_START pid=3272 uid=500 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.832543 sudo[3272]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:54.850146 sudo[3272]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:54.849000 audit[3272]: USER_END pid=3272 uid=500 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.849000 audit[3272]: CRED_DISP pid=3272 uid=500 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.865029 sshd[3270]: Connection closed by 20.61.25.254 port 54188 Sep 4 01:16:54.866584 sshd-session[3264]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:54.866000 audit[3264]: USER_END pid=3264 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.866000 audit[3264]: CRED_DISP pid=3264 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:54.868000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@15-10.0.0.35:22-20.61.25.254:54188 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.869463 systemd[1]: sshd@15-10.0.0.35:22-20.61.25.254:54188.service: Deactivated successfully. Sep 4 01:16:54.870977 systemd[1]: session-19.scope: Deactivated successfully. Sep 4 01:16:54.871602 systemd-logind[2416]: Session 19 logged out. Waiting for processes to exit. Sep 4 01:16:54.872506 systemd-logind[2416]: Removed session 19. Sep 4 01:16:54.991000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@16-10.0.0.35:22-20.61.25.254:54192 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:54.991683 systemd[1]: Started sshd@16-10.0.0.35:22-20.61.25.254:54192.service - OpenSSH per-connection server daemon (20.61.25.254:54192). Sep 4 01:16:55.100000 audit[3280]: USER_ACCT pid=3280 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.101860 sshd[3280]: Accepted publickey for core from 20.61.25.254 port 54192 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:55.102000 audit[3280]: CRED_ACQ pid=3280 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.102000 audit[3280]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fffc230a310 a2=3 a3=0 items=0 ppid=1 pid=3280 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=20 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:55.102000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:55.103396 sshd-session[3280]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:55.107921 systemd-logind[2416]: New session 20 of user core. Sep 4 01:16:55.117030 systemd[1]: Started session-20.scope - Session 20 of User core. Sep 4 01:16:55.118000 audit[3280]: USER_START pid=3280 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.119000 audit[3284]: CRED_ACQ pid=3284 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.139000 audit[3286]: USER_ACCT pid=3286 uid=500 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.140774 sudo[3286]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:55.140000 audit[3286]: CRED_REFR pid=3286 uid=500 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.140000 audit[3286]: USER_START pid=3286 uid=500 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.141013 sudo[3286]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:55.157000 audit[3286]: USER_END pid=3286 uid=500 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.158024 sudo[3286]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:55.157000 audit[3286]: CRED_DISP pid=3286 uid=500 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.172829 sshd[3284]: Connection closed by 20.61.25.254 port 54192 Sep 4 01:16:55.173168 sshd-session[3280]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:55.173000 audit[3280]: USER_END pid=3280 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.173000 audit[3280]: CRED_DISP pid=3280 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.176556 systemd-logind[2416]: Session 20 logged out. Waiting for processes to exit. Sep 4 01:16:55.176737 systemd[1]: sshd@16-10.0.0.35:22-20.61.25.254:54192.service: Deactivated successfully. Sep 4 01:16:55.176000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@16-10.0.0.35:22-20.61.25.254:54192 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.178203 systemd[1]: session-20.scope: Deactivated successfully. Sep 4 01:16:55.179486 systemd-logind[2416]: Removed session 20. Sep 4 01:16:55.298460 systemd[1]: Started sshd@17-10.0.0.35:22-20.61.25.254:54206.service - OpenSSH per-connection server daemon (20.61.25.254:54206). Sep 4 01:16:55.297000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@17-10.0.0.35:22-20.61.25.254:54206 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.410000 audit[3294]: USER_ACCT pid=3294 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.411761 sshd[3294]: Accepted publickey for core from 20.61.25.254 port 54206 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:55.411000 audit[3294]: CRED_ACQ pid=3294 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.411000 audit[3294]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffdce354600 a2=3 a3=0 items=0 ppid=1 pid=3294 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=21 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:55.411000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:55.412728 sshd-session[3294]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:55.416923 systemd-logind[2416]: New session 21 of user core. Sep 4 01:16:55.428003 systemd[1]: Started session-21.scope - Session 21 of User core. Sep 4 01:16:55.429000 audit[3294]: USER_START pid=3294 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.430000 audit[3298]: CRED_ACQ pid=3298 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.450000 audit[3300]: USER_ACCT pid=3300 uid=500 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.451974 sudo[3300]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:55.451000 audit[3300]: CRED_REFR pid=3300 uid=500 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.451000 audit[3300]: USER_START pid=3300 uid=500 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.452198 sudo[3300]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:55.470237 sudo[3300]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:55.469000 audit[3300]: USER_END pid=3300 uid=500 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.469000 audit[3300]: CRED_DISP pid=3300 uid=500 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.485260 sshd[3298]: Connection closed by 20.61.25.254 port 54206 Sep 4 01:16:55.486022 sshd-session[3294]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:55.486000 audit[3294]: USER_END pid=3294 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.486000 audit[3294]: CRED_DISP pid=3294 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.487000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@17-10.0.0.35:22-20.61.25.254:54206 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.488468 systemd[1]: sshd@17-10.0.0.35:22-20.61.25.254:54206.service: Deactivated successfully. Sep 4 01:16:55.490081 systemd[1]: session-21.scope: Deactivated successfully. Sep 4 01:16:55.491178 systemd-logind[2416]: Session 21 logged out. Waiting for processes to exit. Sep 4 01:16:55.492307 systemd-logind[2416]: Removed session 21. Sep 4 01:16:55.614000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@18-10.0.0.35:22-20.61.25.254:54214 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.615296 systemd[1]: Started sshd@18-10.0.0.35:22-20.61.25.254:54214.service - OpenSSH per-connection server daemon (20.61.25.254:54214). Sep 4 01:16:55.727000 audit[3308]: USER_ACCT pid=3308 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.728968 sshd[3308]: Accepted publickey for core from 20.61.25.254 port 54214 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:55.728000 audit[3308]: CRED_ACQ pid=3308 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.728000 audit[3308]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffdc87a62a0 a2=3 a3=0 items=0 ppid=1 pid=3308 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=22 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:55.728000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:55.730037 sshd-session[3308]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:55.734159 systemd-logind[2416]: New session 22 of user core. Sep 4 01:16:55.743001 systemd[1]: Started session-22.scope - Session 22 of User core. Sep 4 01:16:55.744000 audit[3308]: USER_START pid=3308 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.745000 audit[3312]: CRED_ACQ pid=3312 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.765000 audit[3314]: USER_ACCT pid=3314 uid=500 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.766776 sudo[3314]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:55.766000 audit[3314]: CRED_REFR pid=3314 uid=500 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.766000 audit[3314]: USER_START pid=3314 uid=500 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.767052 sudo[3314]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:55.784853 sudo[3314]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:55.784000 audit[3314]: USER_END pid=3314 uid=500 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.784000 audit[3314]: CRED_DISP pid=3314 uid=500 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.799611 sshd[3312]: Connection closed by 20.61.25.254 port 54214 Sep 4 01:16:55.799979 sshd-session[3308]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:55.800000 audit[3308]: USER_END pid=3308 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.800000 audit[3308]: CRED_DISP pid=3308 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:55.803362 systemd[1]: sshd@18-10.0.0.35:22-20.61.25.254:54214.service: Deactivated successfully. Sep 4 01:16:55.802000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@18-10.0.0.35:22-20.61.25.254:54214 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:55.804951 systemd[1]: session-22.scope: Deactivated successfully. Sep 4 01:16:55.805649 systemd-logind[2416]: Session 22 logged out. Waiting for processes to exit. Sep 4 01:16:55.806797 systemd-logind[2416]: Removed session 22. Sep 4 01:16:55.927256 systemd[1]: Started sshd@19-10.0.0.35:22-20.61.25.254:41284.service - OpenSSH per-connection server daemon (20.61.25.254:41284). Sep 4 01:16:55.926000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@19-10.0.0.35:22-20.61.25.254:41284 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.036000 audit[3322]: USER_ACCT pid=3322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.037458 sshd[3322]: Accepted publickey for core from 20.61.25.254 port 41284 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:56.037000 audit[3322]: CRED_ACQ pid=3322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.037000 audit[3322]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffd1f1da130 a2=3 a3=0 items=0 ppid=1 pid=3322 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=23 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:56.037000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:56.038970 sshd-session[3322]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:56.043281 systemd-logind[2416]: New session 23 of user core. Sep 4 01:16:56.052023 systemd[1]: Started session-23.scope - Session 23 of User core. Sep 4 01:16:56.053000 audit[3322]: USER_START pid=3322 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.054000 audit[3326]: CRED_ACQ pid=3326 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.074000 audit[3328]: USER_ACCT pid=3328 uid=500 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.075883 sudo[3328]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:56.075000 audit[3328]: CRED_REFR pid=3328 uid=500 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.075000 audit[3328]: USER_START pid=3328 uid=500 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.076107 sudo[3328]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:56.091000 audit[3328]: USER_END pid=3328 uid=500 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.092288 sudo[3328]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:56.091000 audit[3328]: CRED_DISP pid=3328 uid=500 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.107073 sshd[3326]: Connection closed by 20.61.25.254 port 41284 Sep 4 01:16:56.108682 sshd-session[3322]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:56.108000 audit[3322]: USER_END pid=3322 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.108000 audit[3322]: CRED_DISP pid=3322 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.110000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@19-10.0.0.35:22-20.61.25.254:41284 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.111317 systemd[1]: sshd@19-10.0.0.35:22-20.61.25.254:41284.service: Deactivated successfully. Sep 4 01:16:56.112981 systemd[1]: session-23.scope: Deactivated successfully. Sep 4 01:16:56.114256 systemd-logind[2416]: Session 23 logged out. Waiting for processes to exit. Sep 4 01:16:56.115410 systemd-logind[2416]: Removed session 23. Sep 4 01:16:56.242000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@20-10.0.0.35:22-20.61.25.254:41286 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.243500 systemd[1]: Started sshd@20-10.0.0.35:22-20.61.25.254:41286.service - OpenSSH per-connection server daemon (20.61.25.254:41286). Sep 4 01:16:56.352000 audit[3336]: USER_ACCT pid=3336 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.354304 sshd[3336]: Accepted publickey for core from 20.61.25.254 port 41286 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:56.354000 audit[3336]: CRED_ACQ pid=3336 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.354000 audit[3336]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffdf2430680 a2=3 a3=0 items=0 ppid=1 pid=3336 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=24 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:56.354000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:56.355906 sshd-session[3336]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:56.360209 systemd-logind[2416]: New session 24 of user core. Sep 4 01:16:56.364010 systemd[1]: Started session-24.scope - Session 24 of User core. Sep 4 01:16:56.364000 audit[3336]: USER_START pid=3336 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.366000 audit[3340]: CRED_ACQ pid=3340 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.386000 audit[3342]: USER_ACCT pid=3342 uid=500 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.387962 sudo[3342]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:56.388171 sudo[3342]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:56.387000 audit[3342]: CRED_REFR pid=3342 uid=500 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.387000 audit[3342]: USER_START pid=3342 uid=500 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.405167 sudo[3342]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:56.404000 audit[3342]: USER_END pid=3342 uid=500 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.404000 audit[3342]: CRED_DISP pid=3342 uid=500 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.419953 sshd[3340]: Connection closed by 20.61.25.254 port 41286 Sep 4 01:16:56.420982 sshd-session[3336]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:56.421000 audit[3336]: USER_END pid=3336 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.421000 audit[3336]: CRED_DISP pid=3336 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.424327 systemd-logind[2416]: Session 24 logged out. Waiting for processes to exit. Sep 4 01:16:56.424464 systemd[1]: sshd@20-10.0.0.35:22-20.61.25.254:41286.service: Deactivated successfully. Sep 4 01:16:56.423000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@20-10.0.0.35:22-20.61.25.254:41286 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.426067 systemd[1]: session-24.scope: Deactivated successfully. Sep 4 01:16:56.427615 systemd-logind[2416]: Removed session 24. Sep 4 01:16:56.547279 systemd[1]: Started sshd@21-10.0.0.35:22-20.61.25.254:41300.service - OpenSSH per-connection server daemon (20.61.25.254:41300). Sep 4 01:16:56.546000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@21-10.0.0.35:22-20.61.25.254:41300 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.657000 audit[3350]: USER_ACCT pid=3350 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.658717 sshd[3350]: Accepted publickey for core from 20.61.25.254 port 41300 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:56.658000 audit[3350]: CRED_ACQ pid=3350 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.658000 audit[3350]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe84aef710 a2=3 a3=0 items=0 ppid=1 pid=3350 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=25 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:56.658000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:56.659795 sshd-session[3350]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:56.663876 systemd-logind[2416]: New session 25 of user core. Sep 4 01:16:56.666998 systemd[1]: Started session-25.scope - Session 25 of User core. Sep 4 01:16:56.667000 audit[3350]: USER_START pid=3350 uid=0 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.669000 audit[3354]: CRED_ACQ pid=3354 uid=0 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.691000 audit[3356]: USER_ACCT pid=3356 uid=500 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.692620 sudo[3356]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:56.691000 audit[3356]: CRED_REFR pid=3356 uid=500 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.692899 sudo[3356]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:56.692000 audit[3356]: USER_START pid=3356 uid=500 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.714973 sudo[3356]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:56.714000 audit[3356]: USER_END pid=3356 uid=500 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.714000 audit[3356]: CRED_DISP pid=3356 uid=500 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.729726 sshd[3354]: Connection closed by 20.61.25.254 port 41300 Sep 4 01:16:56.730078 sshd-session[3350]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:56.730000 audit[3350]: USER_END pid=3350 uid=0 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.730000 audit[3350]: CRED_DISP pid=3350 uid=0 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.733155 systemd[1]: sshd@21-10.0.0.35:22-20.61.25.254:41300.service: Deactivated successfully. Sep 4 01:16:56.732000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@21-10.0.0.35:22-20.61.25.254:41300 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.734571 systemd[1]: session-25.scope: Deactivated successfully. Sep 4 01:16:56.735251 systemd-logind[2416]: Session 25 logged out. Waiting for processes to exit. Sep 4 01:16:56.736227 systemd-logind[2416]: Removed session 25. Sep 4 01:16:56.858338 systemd[1]: Started sshd@22-10.0.0.35:22-20.61.25.254:41308.service - OpenSSH per-connection server daemon (20.61.25.254:41308). Sep 4 01:16:56.857000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@22-10.0.0.35:22-20.61.25.254:41308 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:56.972000 audit[3364]: USER_ACCT pid=3364 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.973559 sshd[3364]: Accepted publickey for core from 20.61.25.254 port 41308 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:56.973000 audit[3364]: CRED_ACQ pid=3364 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.973000 audit[3364]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fff72fcdc40 a2=3 a3=0 items=0 ppid=1 pid=3364 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=26 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:56.973000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:56.974688 sshd-session[3364]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:56.978921 systemd-logind[2416]: New session 26 of user core. Sep 4 01:16:56.990033 systemd[1]: Started session-26.scope - Session 26 of User core. Sep 4 01:16:56.991000 audit[3364]: USER_START pid=3364 uid=0 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:56.992000 audit[3368]: CRED_ACQ pid=3368 uid=0 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.013000 audit[3370]: USER_ACCT pid=3370 uid=500 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.014254 sudo[3370]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:57.013000 audit[3370]: CRED_REFR pid=3370 uid=500 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.013000 audit[3370]: USER_START pid=3370 uid=500 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.014493 sudo[3370]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:57.028000 audit[3370]: USER_END pid=3370 uid=500 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.029137 sudo[3370]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:57.028000 audit[3370]: CRED_DISP pid=3370 uid=500 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.044130 sshd[3368]: Connection closed by 20.61.25.254 port 41308 Sep 4 01:16:57.044485 sshd-session[3364]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:57.044000 audit[3364]: USER_END pid=3364 uid=0 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.044000 audit[3364]: CRED_DISP pid=3364 uid=0 auid=500 ses=26 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.047504 systemd[1]: sshd@22-10.0.0.35:22-20.61.25.254:41308.service: Deactivated successfully. Sep 4 01:16:57.046000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@22-10.0.0.35:22-20.61.25.254:41308 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.048812 systemd[1]: session-26.scope: Deactivated successfully. Sep 4 01:16:57.049534 systemd-logind[2416]: Session 26 logged out. Waiting for processes to exit. Sep 4 01:16:57.050702 systemd-logind[2416]: Removed session 26. Sep 4 01:16:57.171000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@23-10.0.0.35:22-20.61.25.254:41322 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.172069 systemd[1]: Started sshd@23-10.0.0.35:22-20.61.25.254:41322.service - OpenSSH per-connection server daemon (20.61.25.254:41322). Sep 4 01:16:57.221130 systemd[1]: var-lib-docker-overlay2-1e560a6efe3397013d8fc8429a35015ba7de9a038a054df35574429b3f363ca8-merged.mount: Deactivated successfully. Sep 4 01:16:57.286000 audit[3378]: USER_ACCT pid=3378 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.287695 sshd[3378]: Accepted publickey for core from 20.61.25.254 port 41322 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:57.287000 audit[3378]: CRED_ACQ pid=3378 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.288000 audit[3378]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffd0c53fef0 a2=3 a3=0 items=0 ppid=1 pid=3378 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=27 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:57.288000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:57.289271 sshd-session[3378]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:57.293688 systemd-logind[2416]: New session 27 of user core. Sep 4 01:16:57.299998 systemd[1]: Started session-27.scope - Session 27 of User core. Sep 4 01:16:57.301000 audit[3378]: USER_START pid=3378 uid=0 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.302000 audit[3382]: CRED_ACQ pid=3382 uid=0 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.323000 audit[3384]: USER_ACCT pid=3384 uid=500 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.324390 sudo[3384]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:57.323000 audit[3384]: CRED_REFR pid=3384 uid=500 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.323000 audit[3384]: USER_START pid=3384 uid=500 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.324612 sudo[3384]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:57.340000 audit[3384]: USER_END pid=3384 uid=500 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.341085 sudo[3384]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:57.340000 audit[3384]: CRED_DISP pid=3384 uid=500 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.355850 sshd[3382]: Connection closed by 20.61.25.254 port 41322 Sep 4 01:16:57.356195 sshd-session[3378]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:57.356000 audit[3378]: USER_END pid=3378 uid=0 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.356000 audit[3378]: CRED_DISP pid=3378 uid=0 auid=500 ses=27 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.359352 systemd[1]: sshd@23-10.0.0.35:22-20.61.25.254:41322.service: Deactivated successfully. Sep 4 01:16:57.358000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@23-10.0.0.35:22-20.61.25.254:41322 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.998680 kernel: kauditd_printk_skb: 259 callbacks suppressed Sep 4 01:16:57.998734 kernel: audit: type=1130 audit(1788484617.481:515): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@24-10.0.0.35:22-20.61.25.254:41324 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.998750 kernel: audit: type=1101 audit(1788484617.596:516): pid=3392 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.998761 kernel: audit: type=1103 audit(1788484617.597:517): pid=3392 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.998779 kernel: audit: type=1006 audit(1788484617.597:518): pid=3392 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=28 res=1 Sep 4 01:16:57.998791 kernel: audit: type=1300 audit(1788484617.597:518): arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe868ead80 a2=3 a3=0 items=0 ppid=1 pid=3392 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=28 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:57.998802 kernel: audit: type=1327 audit(1788484617.597:518): proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:57.998811 kernel: audit: type=1105 audit(1788484617.614:519): pid=3392 uid=0 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.998823 kernel: audit: type=1103 audit(1788484617.616:520): pid=3396 uid=0 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.998851 kernel: audit: type=1101 audit(1788484617.638:521): pid=3398 uid=500 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.998883 kernel: audit: type=1110 audit(1788484617.638:522): pid=3398 uid=500 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.481000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@24-10.0.0.35:22-20.61.25.254:41324 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.596000 audit[3392]: USER_ACCT pid=3392 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.597000 audit[3392]: CRED_ACQ pid=3392 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.597000 audit[3392]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe868ead80 a2=3 a3=0 items=0 ppid=1 pid=3392 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=28 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:57.597000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:57.614000 audit[3392]: USER_START pid=3392 uid=0 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.616000 audit[3396]: CRED_ACQ pid=3396 uid=0 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.638000 audit[3398]: USER_ACCT pid=3398 uid=500 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.638000 audit[3398]: CRED_REFR pid=3398 uid=500 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.638000 audit[3398]: USER_START pid=3398 uid=500 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.653000 audit[3398]: USER_END pid=3398 uid=500 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.653000 audit[3398]: CRED_DISP pid=3398 uid=500 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.669000 audit[3392]: USER_END pid=3392 uid=0 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.669000 audit[3392]: CRED_DISP pid=3392 uid=0 auid=500 ses=28 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.670000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@24-10.0.0.35:22-20.61.25.254:41324 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.794000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@25-10.0.0.35:22-20.61.25.254:41334 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.905000 audit[3405]: USER_ACCT pid=3405 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.906000 audit[3405]: CRED_ACQ pid=3405 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.906000 audit[3405]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fffae863560 a2=3 a3=0 items=0 ppid=1 pid=3405 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=29 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:57.906000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:57.918000 audit[3405]: USER_START pid=3405 uid=0 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.919000 audit[3409]: CRED_ACQ pid=3409 uid=0 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.940000 audit[3411]: USER_ACCT pid=3411 uid=500 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.940000 audit[3411]: CRED_REFR pid=3411 uid=500 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.940000 audit[3411]: USER_START pid=3411 uid=500 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.967000 audit[3411]: USER_END pid=3411 uid=500 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.967000 audit[3411]: CRED_DISP pid=3411 uid=500 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.982000 audit[3405]: USER_END pid=3405 uid=0 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.983000 audit[3405]: CRED_DISP pid=3405 uid=0 auid=500 ses=29 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:57.984000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@25-10.0.0.35:22-20.61.25.254:41334 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.360770 systemd[1]: session-27.scope: Deactivated successfully. Sep 4 01:16:57.598643 sshd-session[3392]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:57.361532 systemd-logind[2416]: Session 27 logged out. Waiting for processes to exit. Sep 4 01:16:57.639165 sudo[3398]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:58.000281 sshd[3392]: Accepted publickey for core from 20.61.25.254 port 41324 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:57.362552 systemd-logind[2416]: Removed session 27. Sep 4 01:16:57.639323 sudo[3398]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:58.000463 sshd[3396]: Connection closed by 20.61.25.254 port 41324 Sep 4 01:16:58.000516 sshd[3405]: Accepted publickey for core from 20.61.25.254 port 41334 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:57.482460 systemd[1]: Started sshd@24-10.0.0.35:22-20.61.25.254:41324.service - OpenSSH per-connection server daemon (20.61.25.254:41324). Sep 4 01:16:57.654167 sudo[3398]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:58.002062 sshd[3409]: Connection closed by 20.61.25.254 port 41334 Sep 4 01:16:57.605498 systemd-logind[2416]: New session 28 of user core. Sep 4 01:16:57.668933 sshd-session[3392]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:57.610031 systemd[1]: Started session-28.scope - Session 28 of User core. Sep 4 01:16:57.907883 sshd-session[3405]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:58.107000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@26-10.0.0.35:22-20.61.25.254:41344 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.219000 audit[3420]: USER_ACCT pid=3420 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.220000 audit[3420]: CRED_ACQ pid=3420 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.220000 audit[3420]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe4375e6c0 a2=3 a3=0 items=0 ppid=1 pid=3420 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=30 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:58.220000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:58.230000 audit[3420]: USER_START pid=3420 uid=0 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.232000 audit[3424]: CRED_ACQ pid=3424 uid=0 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.254000 audit[3426]: USER_ACCT pid=3426 uid=500 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.254000 audit[3426]: CRED_REFR pid=3426 uid=500 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.254000 audit[3426]: USER_START pid=3426 uid=500 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.272000 audit[3426]: USER_END pid=3426 uid=500 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.272000 audit[3426]: CRED_DISP pid=3426 uid=500 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.288000 audit[3420]: USER_END pid=3420 uid=0 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.289000 audit[3420]: CRED_DISP pid=3420 uid=0 auid=500 ses=30 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.290000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@26-10.0.0.35:22-20.61.25.254:41344 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.416000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@27-10.0.0.35:22-20.61.25.254:41348 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.531000 audit[3433]: USER_ACCT pid=3433 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.532000 audit[3433]: CRED_ACQ pid=3433 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.532000 audit[3433]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffdb0ff0810 a2=3 a3=0 items=0 ppid=1 pid=3433 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=31 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:58.532000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:58.545000 audit[3433]: USER_START pid=3433 uid=0 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.546000 audit[3437]: CRED_ACQ pid=3437 uid=0 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.567000 audit[3439]: USER_ACCT pid=3439 uid=500 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.567000 audit[3439]: CRED_REFR pid=3439 uid=500 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.567000 audit[3439]: USER_START pid=3439 uid=500 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.580000 audit[3439]: USER_END pid=3439 uid=500 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.580000 audit[3439]: CRED_DISP pid=3439 uid=500 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.596000 audit[3433]: USER_END pid=3433 uid=0 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.596000 audit[3433]: CRED_DISP pid=3433 uid=0 auid=500 ses=31 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.598000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@27-10.0.0.35:22-20.61.25.254:41348 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.725000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@28-10.0.0.35:22-20.61.25.254:41354 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:57.671460 systemd[1]: sshd@24-10.0.0.35:22-20.61.25.254:41324.service: Deactivated successfully. Sep 4 01:16:57.941329 sudo[3411]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:57.672806 systemd[1]: session-28.scope: Deactivated successfully. Sep 4 01:16:58.811988 sshd[3420]: Accepted publickey for core from 20.61.25.254 port 41344 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:57.941497 sudo[3411]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:57.674049 systemd-logind[2416]: Session 28 logged out. Waiting for processes to exit. Sep 4 01:16:58.812235 sshd[3424]: Connection closed by 20.61.25.254 port 41344 Sep 4 01:16:58.812301 sshd[3433]: Accepted publickey for core from 20.61.25.254 port 41348 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:57.967890 sudo[3411]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:57.674573 systemd-logind[2416]: Removed session 28. Sep 4 01:16:58.812507 sshd[3437]: Connection closed by 20.61.25.254 port 41348 Sep 4 01:16:57.982950 sshd-session[3405]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:57.795333 systemd[1]: Started sshd@25-10.0.0.35:22-20.61.25.254:41334.service - OpenSSH per-connection server daemon (20.61.25.254:41334). Sep 4 01:16:58.221759 sshd-session[3420]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:57.911988 systemd-logind[2416]: New session 29 of user core. Sep 4 01:16:58.255083 sudo[3426]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:57.917012 systemd[1]: Started session-29.scope - Session 29 of User core. Sep 4 01:16:58.255253 sudo[3426]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:57.985562 systemd[1]: sshd@25-10.0.0.35:22-20.61.25.254:41334.service: Deactivated successfully. Sep 4 01:16:58.273525 sudo[3426]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:57.987047 systemd[1]: session-29.scope: Deactivated successfully. Sep 4 01:16:58.288733 sshd-session[3420]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:57.987699 systemd-logind[2416]: Session 29 logged out. Waiting for processes to exit. Sep 4 01:16:58.533555 sshd-session[3433]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:57.988730 systemd-logind[2416]: Removed session 29. Sep 4 01:16:58.568231 sudo[3439]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:58.108359 systemd[1]: Started sshd@26-10.0.0.35:22-20.61.25.254:41344.service - OpenSSH per-connection server daemon (20.61.25.254:41344). Sep 4 01:16:58.568424 sudo[3439]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:58.226017 systemd-logind[2416]: New session 30 of user core. Sep 4 01:16:58.581044 sudo[3439]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:58.229982 systemd[1]: Started session-30.scope - Session 30 of User core. Sep 4 01:16:58.596162 sshd-session[3433]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:58.291475 systemd[1]: sshd@26-10.0.0.35:22-20.61.25.254:41344.service: Deactivated successfully. Sep 4 01:16:58.292954 systemd[1]: session-30.scope: Deactivated successfully. Sep 4 01:16:58.293542 systemd-logind[2416]: Session 30 logged out. Waiting for processes to exit. Sep 4 01:16:58.294651 systemd-logind[2416]: Removed session 30. Sep 4 01:16:58.417572 systemd[1]: Started sshd@27-10.0.0.35:22-20.61.25.254:41348.service - OpenSSH per-connection server daemon (20.61.25.254:41348). Sep 4 01:16:58.537725 systemd-logind[2416]: New session 31 of user core. Sep 4 01:16:58.543993 systemd[1]: Started session-31.scope - Session 31 of User core. Sep 4 01:16:58.599003 systemd[1]: sshd@27-10.0.0.35:22-20.61.25.254:41348.service: Deactivated successfully. Sep 4 01:16:58.600510 systemd[1]: session-31.scope: Deactivated successfully. Sep 4 01:16:58.601785 systemd-logind[2416]: Session 31 logged out. Waiting for processes to exit. Sep 4 01:16:58.602458 systemd-logind[2416]: Removed session 31. Sep 4 01:16:58.726388 systemd[1]: Started sshd@28-10.0.0.35:22-20.61.25.254:41354.service - OpenSSH per-connection server daemon (20.61.25.254:41354). Sep 4 01:16:58.834000 audit[3446]: USER_ACCT pid=3446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.835769 sshd[3446]: Accepted publickey for core from 20.61.25.254 port 41354 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:58.835000 audit[3446]: CRED_ACQ pid=3446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.835000 audit[3446]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffed58fbda0 a2=3 a3=0 items=0 ppid=1 pid=3446 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=32 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:58.835000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:58.836926 sshd-session[3446]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:58.841273 systemd-logind[2416]: New session 32 of user core. Sep 4 01:16:58.849993 systemd[1]: Started session-32.scope - Session 32 of User core. Sep 4 01:16:58.851000 audit[3446]: USER_START pid=3446 uid=0 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.852000 audit[3452]: CRED_ACQ pid=3452 uid=0 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.872000 audit[3454]: USER_ACCT pid=3454 uid=500 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.873818 sudo[3454]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:58.873000 audit[3454]: CRED_REFR pid=3454 uid=500 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.873000 audit[3454]: USER_START pid=3454 uid=500 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.874082 sudo[3454]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:58.896988 sudo[3454]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:58.896000 audit[3454]: USER_END pid=3454 uid=500 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.896000 audit[3454]: CRED_DISP pid=3454 uid=500 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.911672 sshd[3452]: Connection closed by 20.61.25.254 port 41354 Sep 4 01:16:58.913171 sshd-session[3446]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:58.913000 audit[3446]: USER_END pid=3446 uid=0 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.913000 audit[3446]: CRED_DISP pid=3446 uid=0 auid=500 ses=32 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:58.916145 systemd[1]: sshd@28-10.0.0.35:22-20.61.25.254:41354.service: Deactivated successfully. Sep 4 01:16:58.915000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@28-10.0.0.35:22-20.61.25.254:41354 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:58.917659 systemd[1]: session-32.scope: Deactivated successfully. Sep 4 01:16:58.918723 systemd-logind[2416]: Session 32 logged out. Waiting for processes to exit. Sep 4 01:16:58.919421 systemd-logind[2416]: Removed session 32. Sep 4 01:16:59.044320 systemd[1]: Started sshd@29-10.0.0.35:22-20.61.25.254:41364.service - OpenSSH per-connection server daemon (20.61.25.254:41364). Sep 4 01:16:59.043000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@29-10.0.0.35:22-20.61.25.254:41364 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.153000 audit[3462]: USER_ACCT pid=3462 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.154759 sshd[3462]: Accepted publickey for core from 20.61.25.254 port 41364 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:59.154000 audit[3462]: CRED_ACQ pid=3462 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.154000 audit[3462]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffca0385d50 a2=3 a3=0 items=0 ppid=1 pid=3462 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=33 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:59.154000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:59.156148 sshd-session[3462]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:59.160298 systemd-logind[2416]: New session 33 of user core. Sep 4 01:16:59.168017 systemd[1]: Started session-33.scope - Session 33 of User core. Sep 4 01:16:59.169000 audit[3462]: USER_START pid=3462 uid=0 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.170000 audit[3466]: CRED_ACQ pid=3466 uid=0 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.190000 audit[3468]: USER_ACCT pid=3468 uid=500 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.191755 sudo[3468]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:59.191000 audit[3468]: CRED_REFR pid=3468 uid=500 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.192034 sudo[3468]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:59.191000 audit[3468]: USER_START pid=3468 uid=500 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.212069 sudo[3468]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:59.211000 audit[3468]: USER_END pid=3468 uid=500 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.211000 audit[3468]: CRED_DISP pid=3468 uid=500 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.226944 sshd[3466]: Connection closed by 20.61.25.254 port 41364 Sep 4 01:16:59.227989 sshd-session[3462]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:59.228000 audit[3462]: USER_END pid=3462 uid=0 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.228000 audit[3462]: CRED_DISP pid=3462 uid=0 auid=500 ses=33 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.231345 systemd-logind[2416]: Session 33 logged out. Waiting for processes to exit. Sep 4 01:16:59.231472 systemd[1]: sshd@29-10.0.0.35:22-20.61.25.254:41364.service: Deactivated successfully. Sep 4 01:16:59.230000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@29-10.0.0.35:22-20.61.25.254:41364 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.233045 systemd[1]: session-33.scope: Deactivated successfully. Sep 4 01:16:59.234414 systemd-logind[2416]: Removed session 33. Sep 4 01:16:59.352000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@30-10.0.0.35:22-20.61.25.254:41376 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.353506 systemd[1]: Started sshd@30-10.0.0.35:22-20.61.25.254:41376.service - OpenSSH per-connection server daemon (20.61.25.254:41376). Sep 4 01:16:59.465000 audit[3476]: USER_ACCT pid=3476 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.466974 sshd[3476]: Accepted publickey for core from 20.61.25.254 port 41376 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:59.466000 audit[3476]: CRED_ACQ pid=3476 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.466000 audit[3476]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fff6622a610 a2=3 a3=0 items=0 ppid=1 pid=3476 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=34 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:59.466000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:59.468044 sshd-session[3476]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:59.472559 systemd-logind[2416]: New session 34 of user core. Sep 4 01:16:59.481002 systemd[1]: Started session-34.scope - Session 34 of User core. Sep 4 01:16:59.482000 audit[3476]: USER_START pid=3476 uid=0 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.483000 audit[3480]: CRED_ACQ pid=3480 uid=0 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.503000 audit[3482]: USER_ACCT pid=3482 uid=500 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.504758 sudo[3482]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:59.504000 audit[3482]: CRED_REFR pid=3482 uid=500 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.504000 audit[3482]: USER_START pid=3482 uid=500 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.505010 sudo[3482]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:59.521951 sudo[3482]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:59.521000 audit[3482]: USER_END pid=3482 uid=500 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.521000 audit[3482]: CRED_DISP pid=3482 uid=500 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.536609 sshd[3480]: Connection closed by 20.61.25.254 port 41376 Sep 4 01:16:59.536970 sshd-session[3476]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:59.537000 audit[3476]: USER_END pid=3476 uid=0 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.537000 audit[3476]: CRED_DISP pid=3476 uid=0 auid=500 ses=34 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.539454 systemd[1]: sshd@30-10.0.0.35:22-20.61.25.254:41376.service: Deactivated successfully. Sep 4 01:16:59.538000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@30-10.0.0.35:22-20.61.25.254:41376 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.541316 systemd[1]: session-34.scope: Deactivated successfully. Sep 4 01:16:59.542405 systemd-logind[2416]: Session 34 logged out. Waiting for processes to exit. Sep 4 01:16:59.543444 systemd-logind[2416]: Removed session 34. Sep 4 01:16:59.665282 systemd[1]: Started sshd@31-10.0.0.35:22-20.61.25.254:41384.service - OpenSSH per-connection server daemon (20.61.25.254:41384). Sep 4 01:16:59.664000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@31-10.0.0.35:22-20.61.25.254:41384 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.775000 audit[3490]: USER_ACCT pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.775000 audit[3490]: CRED_ACQ pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.775000 audit[3490]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fffcdf71d50 a2=3 a3=0 items=0 ppid=1 pid=3490 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=35 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:16:59.775000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:16:59.781144 systemd-logind[2416]: New session 35 of user core. Sep 4 01:16:59.777129 sshd-session[3490]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:16:59.790992 systemd[1]: Started session-35.scope - Session 35 of User core. Sep 4 01:16:59.902778 sshd[3490]: Accepted publickey for core from 20.61.25.254 port 41384 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:16:59.902000 audit[3490]: USER_START pid=3490 uid=0 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.903000 audit[3494]: CRED_ACQ pid=3494 uid=0 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.924000 audit[3496]: USER_ACCT pid=3496 uid=500 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.925587 sudo[3496]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:16:59.924000 audit[3496]: CRED_REFR pid=3496 uid=500 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.924000 audit[3496]: USER_START pid=3496 uid=500 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.925810 sudo[3496]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:16:59.943068 sudo[3496]: pam_unix(sudo:session): session closed for user root Sep 4 01:16:59.942000 audit[3496]: USER_END pid=3496 uid=500 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.942000 audit[3496]: CRED_DISP pid=3496 uid=500 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.957921 sshd[3494]: Connection closed by 20.61.25.254 port 41384 Sep 4 01:16:59.958268 sshd-session[3490]: pam_unix(sshd:session): session closed for user core Sep 4 01:16:59.958000 audit[3490]: USER_END pid=3490 uid=0 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.958000 audit[3490]: CRED_DISP pid=3490 uid=0 auid=500 ses=35 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:16:59.961139 systemd[1]: sshd@31-10.0.0.35:22-20.61.25.254:41384.service: Deactivated successfully. Sep 4 01:16:59.960000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@31-10.0.0.35:22-20.61.25.254:41384 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:16:59.962592 systemd[1]: session-35.scope: Deactivated successfully. Sep 4 01:16:59.963969 systemd-logind[2416]: Session 35 logged out. Waiting for processes to exit. Sep 4 01:16:59.964907 systemd-logind[2416]: Removed session 35. Sep 4 01:17:00.087480 systemd[1]: Started sshd@32-10.0.0.35:22-20.61.25.254:41400.service - OpenSSH per-connection server daemon (20.61.25.254:41400). Sep 4 01:17:00.086000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@32-10.0.0.35:22-20.61.25.254:41400 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.196000 audit[3504]: USER_ACCT pid=3504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.197998 sshd[3504]: Accepted publickey for core from 20.61.25.254 port 41400 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:00.197000 audit[3504]: CRED_ACQ pid=3504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.197000 audit[3504]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fff2cc8b3e0 a2=3 a3=0 items=0 ppid=1 pid=3504 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=36 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:00.197000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:00.199103 sshd-session[3504]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:00.203288 systemd-logind[2416]: New session 36 of user core. Sep 4 01:17:00.208996 systemd[1]: Started session-36.scope - Session 36 of User core. Sep 4 01:17:00.210000 audit[3504]: USER_START pid=3504 uid=0 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.211000 audit[3508]: CRED_ACQ pid=3508 uid=0 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.232000 audit[3510]: USER_ACCT pid=3510 uid=500 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.233124 sudo[3510]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:00.232000 audit[3510]: CRED_REFR pid=3510 uid=500 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.232000 audit[3510]: USER_START pid=3510 uid=500 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.233351 sudo[3510]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:00.250755 sudo[3510]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:00.249000 audit[3510]: USER_END pid=3510 uid=500 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.250000 audit[3510]: CRED_DISP pid=3510 uid=500 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.265386 sshd[3508]: Connection closed by 20.61.25.254 port 41400 Sep 4 01:17:00.266809 sshd-session[3504]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:00.266000 audit[3504]: USER_END pid=3504 uid=0 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.266000 audit[3504]: CRED_DISP pid=3504 uid=0 auid=500 ses=36 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.269148 systemd[1]: sshd@32-10.0.0.35:22-20.61.25.254:41400.service: Deactivated successfully. Sep 4 01:17:00.268000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@32-10.0.0.35:22-20.61.25.254:41400 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.270624 systemd[1]: session-36.scope: Deactivated successfully. Sep 4 01:17:00.272230 systemd-logind[2416]: Session 36 logged out. Waiting for processes to exit. Sep 4 01:17:00.272832 systemd-logind[2416]: Removed session 36. Sep 4 01:17:00.392396 systemd[1]: Started sshd@33-10.0.0.35:22-20.61.25.254:41404.service - OpenSSH per-connection server daemon (20.61.25.254:41404). Sep 4 01:17:00.391000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@33-10.0.0.35:22-20.61.25.254:41404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.506000 audit[3518]: USER_ACCT pid=3518 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.507706 sshd[3518]: Accepted publickey for core from 20.61.25.254 port 41404 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:00.507000 audit[3518]: CRED_ACQ pid=3518 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.507000 audit[3518]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7fffca9acb00 a2=3 a3=0 items=0 ppid=1 pid=3518 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=37 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:00.507000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:00.508604 sshd-session[3518]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:00.512825 systemd-logind[2416]: New session 37 of user core. Sep 4 01:17:00.518013 systemd[1]: Started session-37.scope - Session 37 of User core. Sep 4 01:17:00.519000 audit[3518]: USER_START pid=3518 uid=0 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.520000 audit[3522]: CRED_ACQ pid=3522 uid=0 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.540000 audit[3524]: USER_ACCT pid=3524 uid=500 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.541780 sudo[3524]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:00.541000 audit[3524]: CRED_REFR pid=3524 uid=500 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.541000 audit[3524]: USER_START pid=3524 uid=500 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.557000 audit[3524]: USER_END pid=3524 uid=500 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.557000 audit[3524]: CRED_DISP pid=3524 uid=500 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.573000 audit[3518]: USER_END pid=3518 uid=0 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.573000 audit[3518]: CRED_DISP pid=3518 uid=0 auid=500 ses=37 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.575000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@33-10.0.0.35:22-20.61.25.254:41404 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.703000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@34-10.0.0.35:22-20.61.25.254:41416 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.814000 audit[3532]: USER_ACCT pid=3532 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.814000 audit[3532]: CRED_ACQ pid=3532 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.815000 audit[3532]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffd339fa210 a2=3 a3=0 items=0 ppid=1 pid=3532 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=38 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:00.815000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:00.829000 audit[3532]: USER_START pid=3532 uid=0 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.830000 audit[3536]: CRED_ACQ pid=3536 uid=0 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.851000 audit[3538]: USER_ACCT pid=3538 uid=500 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.851000 audit[3538]: CRED_REFR pid=3538 uid=500 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.851000 audit[3538]: USER_START pid=3538 uid=500 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.869000 audit[3538]: USER_END pid=3538 uid=500 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.869000 audit[3538]: CRED_DISP pid=3538 uid=500 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:00.885000 audit[3532]: USER_END pid=3532 uid=0 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.885000 audit[3532]: CRED_DISP pid=3532 uid=0 auid=500 ses=38 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.887000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@34-10.0.0.35:22-20.61.25.254:41416 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.014000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@35-10.0.0.35:22-20.61.25.254:41420 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.126000 audit[3545]: USER_ACCT pid=3545 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.126000 audit[3545]: CRED_ACQ pid=3545 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.126000 audit[3545]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffd4f397b10 a2=3 a3=0 items=0 ppid=1 pid=3545 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=39 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:01.126000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:01.139000 audit[3545]: USER_START pid=3545 uid=0 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.140000 audit[3549]: CRED_ACQ pid=3549 uid=0 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:00.542034 sudo[3524]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:00.576032 systemd[1]: sshd@33-10.0.0.35:22-20.61.25.254:41404.service: Deactivated successfully. Sep 4 01:17:01.151491 sshd[3522]: Connection closed by 20.61.25.254 port 41404 Sep 4 01:17:00.558726 sudo[3524]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:00.577433 systemd[1]: session-37.scope: Deactivated successfully. Sep 4 01:17:01.152271 sshd[3532]: Accepted publickey for core from 20.61.25.254 port 41416 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:00.573479 sshd-session[3518]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:00.578052 systemd-logind[2416]: Session 37 logged out. Waiting for processes to exit. Sep 4 01:17:01.152576 sshd[3536]: Connection closed by 20.61.25.254 port 41416 Sep 4 01:17:01.152638 sshd[3545]: Accepted publickey for core from 20.61.25.254 port 41420 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:00.816221 sshd-session[3532]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:00.579651 systemd-logind[2416]: Removed session 37. Sep 4 01:17:00.852129 sudo[3538]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:00.704330 systemd[1]: Started sshd@34-10.0.0.35:22-20.61.25.254:41416.service - OpenSSH per-connection server daemon (20.61.25.254:41416). Sep 4 01:17:00.852320 sudo[3538]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:00.820567 systemd-logind[2416]: New session 38 of user core. Sep 4 01:17:00.870094 sudo[3538]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:00.827992 systemd[1]: Started session-38.scope - Session 38 of User core. Sep 4 01:17:00.885172 sshd-session[3532]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:00.887668 systemd[1]: sshd@34-10.0.0.35:22-20.61.25.254:41416.service: Deactivated successfully. Sep 4 01:17:01.128169 sshd-session[3545]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:00.889217 systemd[1]: session-38.scope: Deactivated successfully. Sep 4 01:17:00.890427 systemd-logind[2416]: Session 38 logged out. Waiting for processes to exit. Sep 4 01:17:00.891051 systemd-logind[2416]: Removed session 38. Sep 4 01:17:01.015307 systemd[1]: Started sshd@35-10.0.0.35:22-20.61.25.254:41420.service - OpenSSH per-connection server daemon (20.61.25.254:41420). Sep 4 01:17:01.131958 systemd-logind[2416]: New session 39 of user core. Sep 4 01:17:01.138011 systemd[1]: Started session-39.scope - Session 39 of User core. Sep 4 01:17:01.161000 audit[3552]: USER_ACCT pid=3552 uid=500 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.162702 sudo[3552]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:01.161000 audit[3552]: CRED_REFR pid=3552 uid=500 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.162000 audit[3552]: USER_START pid=3552 uid=500 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.162970 sudo[3552]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:01.179804 sudo[3552]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:01.178000 audit[3552]: USER_END pid=3552 uid=500 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.179000 audit[3552]: CRED_DISP pid=3552 uid=500 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.194563 sshd[3549]: Connection closed by 20.61.25.254 port 41420 Sep 4 01:17:01.194981 sshd-session[3545]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:01.195000 audit[3545]: USER_END pid=3545 uid=0 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.195000 audit[3545]: CRED_DISP pid=3545 uid=0 auid=500 ses=39 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.197761 systemd[1]: sshd@35-10.0.0.35:22-20.61.25.254:41420.service: Deactivated successfully. Sep 4 01:17:01.199075 systemd[1]: session-39.scope: Deactivated successfully. Sep 4 01:17:01.197000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@35-10.0.0.35:22-20.61.25.254:41420 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.200822 systemd-logind[2416]: Session 39 logged out. Waiting for processes to exit. Sep 4 01:17:01.201406 systemd-logind[2416]: Removed session 39. Sep 4 01:17:01.328355 systemd[1]: Started sshd@36-10.0.0.35:22-20.61.25.254:41430.service - OpenSSH per-connection server daemon (20.61.25.254:41430). Sep 4 01:17:01.327000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@36-10.0.0.35:22-20.61.25.254:41430 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.438000 audit[3560]: USER_ACCT pid=3560 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.440015 sshd[3560]: Accepted publickey for core from 20.61.25.254 port 41430 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:01.439000 audit[3560]: CRED_ACQ pid=3560 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.439000 audit[3560]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffdeccd3390 a2=3 a3=0 items=0 ppid=1 pid=3560 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=40 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:01.439000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:01.441201 sshd-session[3560]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:01.445876 systemd-logind[2416]: New session 40 of user core. Sep 4 01:17:01.451016 systemd[1]: Started session-40.scope - Session 40 of User core. Sep 4 01:17:01.452000 audit[3560]: USER_START pid=3560 uid=0 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.454000 audit[3564]: CRED_ACQ pid=3564 uid=0 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.475000 audit[3566]: USER_ACCT pid=3566 uid=500 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.476176 sudo[3566]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:01.475000 audit[3566]: CRED_REFR pid=3566 uid=500 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.475000 audit[3566]: USER_START pid=3566 uid=500 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.476418 sudo[3566]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:01.493113 sudo[3566]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:01.492000 audit[3566]: USER_END pid=3566 uid=500 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.492000 audit[3566]: CRED_DISP pid=3566 uid=500 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.507750 sshd[3564]: Connection closed by 20.61.25.254 port 41430 Sep 4 01:17:01.509286 sshd-session[3560]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:01.509000 audit[3560]: USER_END pid=3560 uid=0 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.509000 audit[3560]: CRED_DISP pid=3560 uid=0 auid=500 ses=40 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.512270 systemd[1]: sshd@36-10.0.0.35:22-20.61.25.254:41430.service: Deactivated successfully. Sep 4 01:17:01.511000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@36-10.0.0.35:22-20.61.25.254:41430 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.514116 systemd[1]: session-40.scope: Deactivated successfully. Sep 4 01:17:01.514916 systemd-logind[2416]: Session 40 logged out. Waiting for processes to exit. Sep 4 01:17:01.516074 systemd-logind[2416]: Removed session 40. Sep 4 01:17:01.632000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@37-10.0.0.35:22-20.61.25.254:41444 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.633466 systemd[1]: Started sshd@37-10.0.0.35:22-20.61.25.254:41444.service - OpenSSH per-connection server daemon (20.61.25.254:41444). Sep 4 01:17:01.744000 audit[3574]: USER_ACCT pid=3574 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.745899 sshd[3574]: Accepted publickey for core from 20.61.25.254 port 41444 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:01.745000 audit[3574]: CRED_ACQ pid=3574 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.745000 audit[3574]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffd0fcd8300 a2=3 a3=0 items=0 ppid=1 pid=3574 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=41 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:01.745000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:01.746582 sshd-session[3574]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:01.750724 systemd-logind[2416]: New session 41 of user core. Sep 4 01:17:01.754012 systemd[1]: Started session-41.scope - Session 41 of User core. Sep 4 01:17:01.755000 audit[3574]: USER_START pid=3574 uid=0 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.756000 audit[3578]: CRED_ACQ pid=3578 uid=0 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.778000 audit[3580]: USER_ACCT pid=3580 uid=500 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.779364 sudo[3580]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:01.778000 audit[3580]: CRED_REFR pid=3580 uid=500 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.778000 audit[3580]: USER_START pid=3580 uid=500 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.779589 sudo[3580]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:01.797015 sudo[3580]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:01.796000 audit[3580]: USER_END pid=3580 uid=500 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.796000 audit[3580]: CRED_DISP pid=3580 uid=500 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.811657 sshd[3578]: Connection closed by 20.61.25.254 port 41444 Sep 4 01:17:01.811966 sshd-session[3574]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:01.813000 audit[3574]: USER_END pid=3574 uid=0 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.813000 audit[3574]: CRED_DISP pid=3574 uid=0 auid=500 ses=41 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:01.816198 systemd[1]: sshd@37-10.0.0.35:22-20.61.25.254:41444.service: Deactivated successfully. Sep 4 01:17:01.815000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@37-10.0.0.35:22-20.61.25.254:41444 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:01.817726 systemd[1]: session-41.scope: Deactivated successfully. Sep 4 01:17:01.818456 systemd-logind[2416]: Session 41 logged out. Waiting for processes to exit. Sep 4 01:17:01.819521 systemd-logind[2416]: Removed session 41. Sep 4 01:17:01.937133 systemd[1]: Started sshd@38-10.0.0.35:22-20.61.25.254:41452.service - OpenSSH per-connection server daemon (20.61.25.254:41452). Sep 4 01:17:01.936000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@38-10.0.0.35:22-20.61.25.254:41452 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.047000 audit[3588]: USER_ACCT pid=3588 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.048860 sshd[3588]: Accepted publickey for core from 20.61.25.254 port 41452 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:02.049000 audit[3588]: CRED_ACQ pid=3588 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.049000 audit[3588]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffc56551a00 a2=3 a3=0 items=0 ppid=1 pid=3588 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=42 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:02.049000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:02.050373 sshd-session[3588]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:02.057052 systemd-logind[2416]: New session 42 of user core. Sep 4 01:17:02.059016 systemd[1]: Started session-42.scope - Session 42 of User core. Sep 4 01:17:02.060000 audit[3588]: USER_START pid=3588 uid=0 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.061000 audit[3595]: CRED_ACQ pid=3595 uid=0 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.082000 audit[3597]: USER_ACCT pid=3597 uid=500 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.083678 sudo[3597]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:02.082000 audit[3597]: CRED_REFR pid=3597 uid=500 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.083000 audit[3597]: USER_START pid=3597 uid=500 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.083933 sudo[3597]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:02.099262 sudo[3597]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:02.098000 audit[3597]: USER_END pid=3597 uid=500 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.098000 audit[3597]: CRED_DISP pid=3597 uid=500 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.114217 sshd[3595]: Connection closed by 20.61.25.254 port 41452 Sep 4 01:17:02.115858 sshd-session[3588]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:02.115000 audit[3588]: USER_END pid=3588 uid=0 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.116000 audit[3588]: CRED_DISP pid=3588 uid=0 auid=500 ses=42 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.118873 systemd[1]: sshd@38-10.0.0.35:22-20.61.25.254:41452.service: Deactivated successfully. Sep 4 01:17:02.118000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@38-10.0.0.35:22-20.61.25.254:41452 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.120483 systemd[1]: session-42.scope: Deactivated successfully. Sep 4 01:17:02.121742 systemd-logind[2416]: Session 42 logged out. Waiting for processes to exit. Sep 4 01:17:02.122499 systemd-logind[2416]: Removed session 42. Sep 4 01:17:02.242000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@39-10.0.0.35:22-20.61.25.254:41468 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.243389 systemd[1]: Started sshd@39-10.0.0.35:22-20.61.25.254:41468.service - OpenSSH per-connection server daemon (20.61.25.254:41468). Sep 4 01:17:02.353000 audit[3605]: USER_ACCT pid=3605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.354000 audit[3605]: CRED_ACQ pid=3605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.354000 audit[3605]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffff02ede40 a2=3 a3=0 items=0 ppid=1 pid=3605 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=43 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:02.354000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:02.355454 sshd-session[3605]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:02.398922 sshd[3605]: Accepted publickey for core from 20.61.25.254 port 41468 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:02.360666 systemd-logind[2416]: New session 43 of user core. Sep 4 01:17:02.368016 systemd[1]: Started session-43.scope - Session 43 of User core. Sep 4 01:17:02.398000 audit[3605]: USER_START pid=3605 uid=0 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.400000 audit[3609]: CRED_ACQ pid=3609 uid=0 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.421000 audit[3611]: USER_ACCT pid=3611 uid=500 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.422029 sudo[3611]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:02.421000 audit[3611]: CRED_REFR pid=3611 uid=500 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.421000 audit[3611]: USER_START pid=3611 uid=500 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.422275 sudo[3611]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:02.440851 sudo[3611]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:02.440000 audit[3611]: USER_END pid=3611 uid=500 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.440000 audit[3611]: CRED_DISP pid=3611 uid=500 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.455632 sshd[3609]: Connection closed by 20.61.25.254 port 41468 Sep 4 01:17:02.455997 sshd-session[3605]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:02.456000 audit[3605]: USER_END pid=3605 uid=0 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.456000 audit[3605]: CRED_DISP pid=3605 uid=0 auid=500 ses=43 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.459160 systemd[1]: sshd@39-10.0.0.35:22-20.61.25.254:41468.service: Deactivated successfully. Sep 4 01:17:02.458000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@39-10.0.0.35:22-20.61.25.254:41468 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.460613 systemd[1]: session-43.scope: Deactivated successfully. Sep 4 01:17:02.461509 systemd-logind[2416]: Session 43 logged out. Waiting for processes to exit. Sep 4 01:17:02.462672 systemd-logind[2416]: Removed session 43. Sep 4 01:17:02.583072 kernel: kauditd_printk_skb: 246 callbacks suppressed Sep 4 01:17:02.583377 kernel: audit: type=1130 audit(1788484622.580:739): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@40-10.0.0.35:22-20.61.25.254:41474 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.580000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@40-10.0.0.35:22-20.61.25.254:41474 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.581226 systemd[1]: Started sshd@40-10.0.0.35:22-20.61.25.254:41474.service - OpenSSH per-connection server daemon (20.61.25.254:41474). Sep 4 01:17:02.696000 audit[3619]: USER_ACCT pid=3619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.697494 sshd[3619]: Accepted publickey for core from 20.61.25.254 port 41474 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:02.698706 sshd-session[3619]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:02.705244 kernel: audit: type=1101 audit(1788484622.696:740): pid=3619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.705327 kernel: audit: type=1103 audit(1788484622.696:741): pid=3619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.696000 audit[3619]: CRED_ACQ pid=3619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.714009 kernel: audit: type=1006 audit(1788484622.696:742): pid=3619 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=44 res=1 Sep 4 01:17:02.714273 kernel: audit: type=1300 audit(1788484622.696:742): arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe21476aa0 a2=3 a3=0 items=0 ppid=1 pid=3619 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:02.696000 audit[3619]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe21476aa0 a2=3 a3=0 items=0 ppid=1 pid=3619 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:02.718277 kernel: audit: type=1327 audit(1788484622.696:742): proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:02.696000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:02.719583 systemd-logind[2416]: New session 44 of user core. Sep 4 01:17:02.724017 systemd[1]: Started session-44.scope - Session 44 of User core. Sep 4 01:17:02.725000 audit[3619]: USER_START pid=3619 uid=0 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.725000 audit[3625]: CRED_ACQ pid=3625 uid=0 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.735182 kernel: audit: type=1105 audit(1788484622.725:743): pid=3619 uid=0 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.735222 kernel: audit: type=1103 audit(1788484622.725:744): pid=3625 uid=0 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.751000 audit[3627]: USER_ACCT pid=3627 uid=500 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.752628 sudo[3627]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:02.753648 sudo[3627]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:02.757049 kernel: audit: type=1101 audit(1788484622.751:745): pid=3627 uid=500 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.757095 kernel: audit: type=1110 audit(1788484622.752:746): pid=3627 uid=500 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.752000 audit[3627]: CRED_REFR pid=3627 uid=500 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.752000 audit[3627]: USER_START pid=3627 uid=500 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.771600 sudo[3627]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:02.770000 audit[3627]: USER_END pid=3627 uid=500 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.770000 audit[3627]: CRED_DISP pid=3627 uid=500 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.786317 sshd[3625]: Connection closed by 20.61.25.254 port 41474 Sep 4 01:17:02.787797 sshd-session[3619]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:02.787000 audit[3619]: USER_END pid=3619 uid=0 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.787000 audit[3619]: CRED_DISP pid=3619 uid=0 auid=500 ses=44 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:02.790650 systemd[1]: sshd@40-10.0.0.35:22-20.61.25.254:41474.service: Deactivated successfully. Sep 4 01:17:02.790000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@40-10.0.0.35:22-20.61.25.254:41474 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:02.792120 systemd[1]: session-44.scope: Deactivated successfully. Sep 4 01:17:02.792808 systemd-logind[2416]: Session 44 logged out. Waiting for processes to exit. Sep 4 01:17:02.794122 systemd-logind[2416]: Removed session 44. Sep 4 01:17:02.913735 systemd[1]: Started sshd@41-10.0.0.35:22-20.61.25.254:41486.service - OpenSSH per-connection server daemon (20.61.25.254:41486). Sep 4 01:17:02.913000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@41-10.0.0.35:22-20.61.25.254:41486 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.014957 containerd[2430]: time="2026-09-04T01:17:03.013955997Z" level=info msg="connecting to shim 08400d25cf57f51a9f3d46eacd654be4ebf55b2ecb960df18747e99abe01766b" address="unix:///run/containerd/s/ce9cc0d88175335ad8c06fbaa89f499365ff81292095ad1d2d4637b356048e18" namespace=moby protocol=ttrpc version=3 Sep 4 01:17:03.023000 audit[3635]: USER_ACCT pid=3635 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.024483 sshd[3635]: Accepted publickey for core from 20.61.25.254 port 41486 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:03.024000 audit[3635]: CRED_ACQ pid=3635 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.024000 audit[3635]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffe8ac5bb60 a2=3 a3=0 items=0 ppid=1 pid=3635 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=45 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.024000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:03.025787 sshd-session[3635]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:03.031108 systemd-logind[2416]: New session 45 of user core. Sep 4 01:17:03.043079 systemd[1]: Started docker-08400d25cf57f51a9f3d46eacd654be4ebf55b2ecb960df18747e99abe01766b.scope - libcontainer container 08400d25cf57f51a9f3d46eacd654be4ebf55b2ecb960df18747e99abe01766b. Sep 4 01:17:03.043881 systemd[1]: Started session-45.scope - Session 45 of User core. Sep 4 01:17:03.045000 audit[3635]: USER_START pid=3635 uid=0 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.047000 audit[3672]: CRED_ACQ pid=3672 uid=0 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.055000 audit: BPF prog-id=71 op=LOAD Sep 4 01:17:03.055000 audit: BPF prog-id=72 op=LOAD Sep 4 01:17:03.055000 audit[3659]: SYSCALL arch=c000003e syscall=321 success=yes exit=21 a0=5 a1=c0001b0238 a2=98 a3=0 items=0 ppid=3648 pid=3659 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.055000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F30383430306432356366353766353161396633643436656163 Sep 4 01:17:03.055000 audit: BPF prog-id=72 op=UNLOAD Sep 4 01:17:03.055000 audit[3659]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=3648 pid=3659 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.055000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F30383430306432356366353766353161396633643436656163 Sep 4 01:17:03.055000 audit: BPF prog-id=73 op=LOAD Sep 4 01:17:03.055000 audit[3659]: SYSCALL arch=c000003e syscall=321 success=yes exit=21 a0=5 a1=c0001b0488 a2=98 a3=0 items=0 ppid=3648 pid=3659 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.055000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F30383430306432356366353766353161396633643436656163 Sep 4 01:17:03.055000 audit: BPF prog-id=74 op=LOAD Sep 4 01:17:03.055000 audit[3659]: SYSCALL arch=c000003e syscall=321 success=yes exit=23 a0=5 a1=c0001b0218 a2=98 a3=0 items=0 ppid=3648 pid=3659 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.055000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F30383430306432356366353766353161396633643436656163 Sep 4 01:17:03.056000 audit: BPF prog-id=74 op=UNLOAD Sep 4 01:17:03.056000 audit[3659]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=17 a1=0 a2=0 a3=0 items=0 ppid=3648 pid=3659 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.056000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F30383430306432356366353766353161396633643436656163 Sep 4 01:17:03.056000 audit: BPF prog-id=73 op=UNLOAD Sep 4 01:17:03.056000 audit[3659]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=15 a1=0 a2=0 a3=0 items=0 ppid=3648 pid=3659 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.056000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F30383430306432356366353766353161396633643436656163 Sep 4 01:17:03.056000 audit: BPF prog-id=75 op=LOAD Sep 4 01:17:03.056000 audit[3659]: SYSCALL arch=c000003e syscall=321 success=yes exit=21 a0=5 a1=c0001b06e8 a2=98 a3=0 items=0 ppid=3648 pid=3659 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.056000 audit: PROCTITLE proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F30383430306432356366353766353161396633643436656163 Sep 4 01:17:03.069000 audit[3680]: USER_ACCT pid=3680 uid=500 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.070000 audit[3680]: CRED_REFR pid=3680 uid=500 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.070927 sudo[3680]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:03.071408 sudo[3680]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:03.070000 audit[3680]: USER_START pid=3680 uid=500 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.089702 sudo[3680]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:03.088000 audit[3680]: USER_END pid=3680 uid=500 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.088000 audit[3680]: CRED_DISP pid=3680 uid=500 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.104977 sshd[3672]: Connection closed by 20.61.25.254 port 41486 Sep 4 01:17:03.104537 sshd-session[3635]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:03.104000 audit[3635]: USER_END pid=3635 uid=0 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.104000 audit[3635]: CRED_DISP pid=3635 uid=0 auid=500 ses=45 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.107478 systemd[1]: sshd@41-10.0.0.35:22-20.61.25.254:41486.service: Deactivated successfully. Sep 4 01:17:03.106000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@41-10.0.0.35:22-20.61.25.254:41486 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.109411 systemd[1]: session-45.scope: Deactivated successfully. Sep 4 01:17:03.110599 systemd-logind[2416]: Session 45 logged out. Waiting for processes to exit. Sep 4 01:17:03.111334 systemd-logind[2416]: Removed session 45. Sep 4 01:17:03.140458 kernel: docker0: port 1(veth03cb1b8) entered blocking state Sep 4 01:17:03.140508 kernel: docker0: port 1(veth03cb1b8) entered disabled state Sep 4 01:17:03.141504 kernel: veth03cb1b8: entered allmulticast mode Sep 4 01:17:03.142549 kernel: veth03cb1b8: entered promiscuous mode Sep 4 01:17:03.137000 audit: ANOM_PROMISCUOUS dev=veth03cb1b8 prom=256 old_prom=0 auid=4294967295 uid=0 gid=0 ses=4294967295 Sep 4 01:17:03.137000 audit[2892]: SYSCALL arch=c000003e syscall=44 success=yes exit=40 a0=c a1=c0008583c0 a2=28 a3=0 items=0 ppid=1 pid=2892 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="dockerd" exe="/usr/bin/dockerd" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.137000 audit: PROCTITLE proctitle=2F7573722F62696E2F646F636B657264002D2D686F73743D66643A2F2F002D2D636F6E7461696E6572643D2F7661722F72756E2F646F636B65722F6C6962636F6E7461696E6572642F646F636B65722D636F6E7461696E6572642E736F636B002D2D73656C696E75782D656E61626C65643D74727565 Sep 4 01:17:03.143969 systemd-networkd[2174]: veth03cb1b8: Link UP Sep 4 01:17:03.227360 systemd[1]: Started sshd@42-10.0.0.35:22-20.61.25.254:41498.service - OpenSSH per-connection server daemon (20.61.25.254:41498). Sep 4 01:17:03.226000 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@42-10.0.0.35:22-20.61.25.254:41498 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.261259 kernel: eth0: renamed from vethe772d78 Sep 4 01:17:03.261339 kernel: docker0: port 1(veth03cb1b8) entered blocking state Sep 4 01:17:03.261365 kernel: docker0: port 1(veth03cb1b8) entered forwarding state Sep 4 01:17:03.261472 systemd-networkd[2174]: veth03cb1b8: Gained carrier Sep 4 01:17:03.261758 systemd-networkd[2174]: docker0: Gained carrier Sep 4 01:17:03.335000 audit[3694]: USER_ACCT pid=3694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_time,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.336775 sshd[3694]: Accepted publickey for core from 20.61.25.254 port 41498 ssh2: RSA SHA256:Ulqp+AFzhAMVpy7hnLexdIdFguScV0qu2sJvDOSrLpI Sep 4 01:17:03.337000 audit[3694]: CRED_ACQ pid=3694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.337000 audit[3694]: SYSCALL arch=c000003e syscall=1 success=yes exit=3 a0=8 a1=7ffdc3934020 a2=3 a3=0 items=0 ppid=1 pid=3694 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=46 comm="sshd-session" exe="/usr/lib64/misc/sshd-session" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.337000 audit: PROCTITLE proctitle=737368642D73657373696F6E3A20636F7265205B707269765D Sep 4 01:17:03.338424 sshd-session[3694]: pam_unix(sshd:session): session opened for user core(uid=500) by core(uid=0) Sep 4 01:17:03.342680 systemd-logind[2416]: New session 46 of user core. Sep 4 01:17:03.349000 audit[3699]: NETFILTER_CFG table=raw:45 family=2 entries=3 op=nft_register_chain pid=3699 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:17:03.349000 audit[3699]: SYSCALL arch=c000003e syscall=46 success=yes exit=720 a0=3 a1=7ffec9835a20 a2=0 a3=0 items=0 ppid=2892 pid=3699 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.349000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D7400726177002D4100505245524F5554494E47002D7000746370002D64003137322E31372E302E32002D2D64706F727400393938380000002D6900646F636B657230002D6A0044524F50 Sep 4 01:17:03.352176 systemd[1]: Started session-46.scope - Session 46 of User core. Sep 4 01:17:03.355000 audit[3694]: USER_START pid=3694 uid=0 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.355000 audit[3702]: NETFILTER_CFG table=nat:46 family=2 entries=1 op=nft_register_rule pid=3702 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:17:03.355000 audit[3702]: SYSCALL arch=c000003e syscall=46 success=yes exit=524 a0=3 a1=7ffc226fa2f0 a2=0 a3=0 items=0 ppid=2892 pid=3702 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.355000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4100444F434B4552002D7000746370002D6400302F30002D2D64706F72740039393838002D6A00444E4154002D2D746F2D64657374696E6174696F6E003137322E31372E302E323A393938380000002D6900646F636B657230 Sep 4 01:17:03.357000 audit[3703]: CRED_ACQ pid=3703 uid=0 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.359000 audit[3706]: NETFILTER_CFG table=filter:47 family=2 entries=1 op=nft_register_rule pid=3706 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:17:03.359000 audit[3706]: SYSCALL arch=c000003e syscall=46 success=yes exit=664 a0=3 a1=7ffd06868ae0 a2=0 a3=0 items=0 ppid=2892 pid=3706 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:03.359000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4900444F434B45520000002D6900646F636B657230002D6F00646F636B657230002D7000746370002D64003137322E31372E302E32002D2D64706F72740039393838002D6A00414343455054 Sep 4 01:17:03.377000 audit[3710]: USER_ACCT pid=3710 uid=500 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.378604 sudo[3710]: core : PWD=/home/core ; USER=root ; COMMAND=/usr/sbin/lsof -i TCP:9988 -s TCP:LISTEN Sep 4 01:17:03.377000 audit[3710]: CRED_REFR pid=3710 uid=500 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.377000 audit[3710]: USER_START pid=3710 uid=500 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.378819 sudo[3710]: pam_unix(sudo:session): session opened for user root(uid=0) by core(uid=500) Sep 4 01:17:03.397000 audit[3710]: USER_END pid=3710 uid=500 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_umask,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.398516 sudo[3710]: pam_unix(sudo:session): session closed for user root Sep 4 01:17:03.397000 audit[3710]: CRED_DISP pid=3710 uid=500 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.413480 sshd[3703]: Connection closed by 20.61.25.254 port 41498 Sep 4 01:17:03.414940 sshd-session[3694]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:03.415000 audit[3694]: USER_END pid=3694 uid=0 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.415000 audit[3694]: CRED_DISP pid=3694 uid=0 auid=500 ses=46 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:03.417946 systemd[1]: sshd@42-10.0.0.35:22-20.61.25.254:41498.service: Deactivated successfully. Sep 4 01:17:03.417000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@42-10.0.0.35:22-20.61.25.254:41498 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:03.419378 systemd[1]: session-46.scope: Deactivated successfully. Sep 4 01:17:03.420702 systemd-logind[2416]: Session 46 logged out. Waiting for processes to exit. Sep 4 01:17:03.421532 systemd-logind[2416]: Removed session 46. Sep 4 01:17:04.048400 systemd[1]: docker-08400d25cf57f51a9f3d46eacd654be4ebf55b2ecb960df18747e99abe01766b.scope: Deactivated successfully. Sep 4 01:17:04.061732 dockerd[2892]: time="2026-09-04T01:17:04.061341924Z" level=info msg="ignoring event" container=08400d25cf57f51a9f3d46eacd654be4ebf55b2ecb960df18747e99abe01766b module=libcontainerd namespace=moby topic=/tasks/delete type="*events.TaskDelete" Sep 4 01:17:04.062088 containerd[2430]: time="2026-09-04T01:17:04.062031456Z" level=info msg="shim disconnected" id=08400d25cf57f51a9f3d46eacd654be4ebf55b2ecb960df18747e99abe01766b namespace=moby Sep 4 01:17:04.062088 containerd[2430]: time="2026-09-04T01:17:04.062065772Z" level=info msg="cleaning up after shim disconnected" id=08400d25cf57f51a9f3d46eacd654be4ebf55b2ecb960df18747e99abe01766b namespace=moby Sep 4 01:17:04.062261 containerd[2430]: time="2026-09-04T01:17:04.062074853Z" level=info msg="cleaning up dead shim" id=08400d25cf57f51a9f3d46eacd654be4ebf55b2ecb960df18747e99abe01766b namespace=moby Sep 4 01:17:04.078000 audit[3759]: NETFILTER_CFG table=raw:48 family=2 entries=1 op=nft_unregister_rule pid=3759 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:17:04.078000 audit[3759]: SYSCALL arch=c000003e syscall=46 success=yes exit=572 a0=3 a1=7ffd5d169640 a2=0 a3=0 items=0 ppid=2892 pid=3759 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:04.078000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D7400726177002D4400505245524F5554494E47002D7000746370002D64003137322E31372E302E32002D2D64706F727400393938380000002D6900646F636B657230002D6A0044524F50 Sep 4 01:17:04.082000 audit[3761]: NETFILTER_CFG table=nat:49 family=2 entries=1 op=nft_unregister_rule pid=3761 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:17:04.082000 audit[3761]: SYSCALL arch=c000003e syscall=46 success=yes exit=528 a0=3 a1=7ffdc172d520 a2=0 a3=0 items=0 ppid=2892 pid=3761 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:04.082000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D74006E6174002D4400444F434B4552002D7000746370002D6400302F30002D2D64706F72740039393838002D6A00444E4154002D2D746F2D64657374696E6174696F6E003137322E31372E302E323A393938380000002D6900646F636B657230 Sep 4 01:17:04.091000 audit[3764]: NETFILTER_CFG table=filter:50 family=2 entries=1 op=nft_unregister_rule pid=3764 subj=system_u:system_r:kernel_t:s0 comm="iptables" Sep 4 01:17:04.091000 audit[3764]: SYSCALL arch=c000003e syscall=46 success=yes exit=656 a0=3 a1=7fff256611c0 a2=0 a3=0 items=0 ppid=2892 pid=3764 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/bin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:04.091000 audit: PROCTITLE proctitle=2F7573722F62696E2F69707461626C6573002D2D77616974002D740066696C746572002D4400444F434B45520000002D6900646F636B657230002D6F00646F636B657230002D7000746370002D64003137322E31372E302E32002D2D64706F72740039393838002D6A00414343455054 Sep 4 01:17:04.113127 systemd-networkd[2174]: veth03cb1b8: Lost carrier Sep 4 01:17:04.114382 kernel: docker0: port 1(veth03cb1b8) entered disabled state Sep 4 01:17:04.114425 kernel: vethe772d78: renamed from eth0 Sep 4 01:17:04.138015 systemd-networkd[2174]: docker0: Lost carrier Sep 4 01:17:04.159687 systemd-networkd[2174]: veth03cb1b8: Link DOWN Sep 4 01:17:04.160900 kernel: docker0: port 1(veth03cb1b8) entered disabled state Sep 4 01:17:04.166066 kernel: veth03cb1b8 (unregistering): left allmulticast mode Sep 4 01:17:04.166113 kernel: veth03cb1b8 (unregistering): left promiscuous mode Sep 4 01:17:04.166126 kernel: docker0: port 1(veth03cb1b8) entered disabled state Sep 4 01:17:04.158000 audit: ANOM_PROMISCUOUS dev=veth03cb1b8 prom=0 old_prom=256 auid=4294967295 uid=0 gid=0 ses=4294967295 Sep 4 01:17:04.158000 audit[2892]: SYSCALL arch=c000003e syscall=44 success=yes exit=32 a0=c a1=c00106cac0 a2=20 a3=0 items=0 ppid=1 pid=2892 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="dockerd" exe="/usr/bin/dockerd" subj=system_u:system_r:kernel_t:s0 key=(null) Sep 4 01:17:04.158000 audit: PROCTITLE proctitle=2F7573722F62696E2F646F636B657264002D2D686F73743D66643A2F2F002D2D636F6E7461696E6572643D2F7661722F72756E2F646F636B65722F6C6962636F6E7461696E6572642F646F636B65722D636F6E7461696E6572642E736F636B002D2D73656C696E75782D656E61626C65643D74727565 Sep 4 01:17:04.253708 systemd[1]: run-docker-netns-403025c146cc.mount: Deactivated successfully. Sep 4 01:17:04.266000 audit: BPF prog-id=71 op=UNLOAD Sep 4 01:17:04.266000 audit: BPF prog-id=75 op=UNLOAD Sep 4 01:17:04.301283 systemd[1]: var-lib-docker-overlay2-1e560a6efe3397013d8fc8429a35015ba7de9a038a054df35574429b3f363ca8-merged.mount: Deactivated successfully. Sep 4 01:17:05.242039 systemd-networkd[2174]: docker0: Gained IPv6LL Sep 4 01:17:07.079712 sshd[3162]: Connection closed by 20.61.25.254 port 54122 Sep 4 01:17:07.080316 sshd-session[3154]: pam_unix(sshd:session): session closed for user core Sep 4 01:17:07.079000 audit[3154]: USER_END pid=3154 uid=0 auid=500 ses=11 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_namespace,pam_keyinit,pam_limits,pam_env,pam_umask,pam_unix,pam_systemd,pam_lastlog,pam_mail acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:07.080000 audit[3154]: CRED_DISP pid=3154 uid=0 auid=500 ses=11 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/lib64/misc/sshd-session" hostname=20.61.25.254 addr=20.61.25.254 terminal=ssh res=success' Sep 4 01:17:07.081000 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-10.0.0.35:22-20.61.25.254:54122 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Sep 4 01:17:07.083510 systemd[1]: sshd@8-10.0.0.35:22-20.61.25.254:54122.service: Deactivated successfully. Sep 4 01:17:07.085499 systemd[1]: session-11.scope: Deactivated successfully. Sep 4 01:17:07.087256 systemd-logind[2416]: Session 11 logged out. Waiting for processes to exit. Sep 4 01:17:07.088035 systemd-logind[2416]: Removed session 11.