How to investigate a hacked site

I have a client site that was hacked.

Their site is using a CMS which I suspect was hacked into (e.g. guessing the password).

How would I go about investigating this?

Do I examine the log files? And if so, are these files located in the /log/ directory?

And if so, what exactly am I looking for? Any tips?

Also, it looks like the log files are only for 7 days. And unfortunately this hack too place on June 27. So is there any way I can get logs for that day?

Thanks for any tips and advice!

Best way is to check log file. If it happens on June 27, please send us ticket with domain name. If log file is available we will copy it to your log directory.

Thanks Manish!