What you did with the web filter and application filter looks in order.
I would recommend that you double check your policies and make sure the source are contained in the policy where the filters are applied on. Also check if there are perhaps any policy above the policy where filters are applied which is allowing access as this will be where the traffic is then going through and not hitting your filters.
Actually i already checked this, in the forward traffic logs the policy applied number is the right policy and it is also in the top of other policies.
It is blocking web sites from same category such as Twitter and Youtube, however Facebook get pass this policy in case SSL deep inspection is applied, but in case of SSL certificate inspection applied it get blocked.
The odd thing is it is blocking anything related to Facebook such as if you googled the word facebook but if you typed the URL https://www.facebook.com it will pass.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.