Virus name
The virus_name field is in most FortiMail log messages where type=virus and subtype=infected.
The field indicates either the name of the virus that was detected (such as virus_name="HTML/Redirector.Q!tr"), or virus_name="Virus-Outbreak" if the file signature is recorded in signature_id instead.
This field is empty if the archive decompression limit or file size limit was exceeded and therefore the scan could not deliver a verdict about whether the attachment contained malware.