I found out that sometimes the Category Description is not logged on the Fortianalyzer. I cannot see any reason why it is happening and it is causing bad results in my report.
URL list is not used in the webfilter profile. The URL category ID is missing.
It is weird, the log detail says that "URL was exempted because it is in the URL filter list" but there is no URL filter list used. Also the next log says "URL belongs to an allowed category in policy" for the same source, destination, port, hostname,... but session ID is different.
I found this on the Fortigate 80D running 5.6.2.
Also Fortigate 240D running 5.6.3.
In all cases i can see the category set to monitor and the default certificate-inspection profile is used.