The document describes an investigation into SQL injection and DNS data exfiltration attacks. In the first part, the analyst uses Kibana to analyze HTTP logs from June 2020 and finds that an SQL injection attack retrieved credit card information from a web server. In the second part, the analyst filters Kibana logs to DNS traffic and finds abnormally long DNS queries to ns.example.com, indicating that data was encoded in the subdomain names to exfiltrate it from the network. The analyst records the DNS client and server IP addresses and determines that strings of numbers and letters in the subdomain names appear to contain exfiltrated text data.