What is the best way to audit file deletion on a cifs share? 
BSM auditing? Should I get the uid of the user (client) that deletes the file ? 

Another question: Is it possible to set the cifs debug mode to a higher level 
then the standard messages logged to /var/log/messages ?
