A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
Article Id 191474
This article describes the signature database behavior if an upgrade is performed.
The version of signature will be replaced during upgrade image, as image include default signature version.

For Example, if the version 6.11 with the signature version 265 is upgraded to the new version 6.22, the signature has been downgraded to the version 250.
This happens because image include default signature version.
There are chances that some signatures will not be present and some custom exceptions using those signatures will be lost.

It is normal for there is no signature ID in the old version.
So to prevent configuration lost, backup the configuration first, then update the latest signature version.
Select 'update-now' button from GUI to get latest one from internet FDS, then restore the configuration, the signature exceptions will not be lost.

Related Articles

Technical Tip: FortiGate VRRP configuration and debug