Hi Chris,
Are you using A-Series or B-Series and what firmware version?
If you are referring to the logs, FortiDDoS logs will show block traffic even in detection mode but its not actually blocking it. It was built that way, possibly to save resources for not having a separate logging for detection mode.
I haven' t use A-series, but in B-Series the older firmware versions (4.0 Build0040 and older) have dos protection enabled by default. To disable it you have to access the CLI and execute " exe dos-control disable" and have to do it again if you reboot the device.
HTH