Virus ID
The virus_id field is in most FortiMail log messages where type=virus and subtype=infected.
The field indicates virus_id=0 if a virus was detected. Its name is recorded in virus_name.
This field is empty if no virus was detected, or if the archive decompression limit or file size limit was exceeded and therefore the scan could not deliver a verdict about whether the attachment contained malware.