Signature ID
The signature_id field is in most FortiMail log messages where type=virus and subtype=infected.
The field indicates either the file signature (checksum or hash) of the malware that was detected, or signature_id=0 if its name is recorded in virus_name instead.
This field is empty if no virus was detected, or if the archive decompression limit or file size limit was exceeded and therefore the scan could not deliver a verdict about whether the attachment contained malware.