On a standalone agent, the history_ids.csv file does not get created after applying a detection policy. The history_ids.csv file contains records of policies that are accepted (successfully applied) or rejected.
On Windows, use the Event Viewer to verify policy application. If a prevention policy is applied to the agent, you require permission in the policy to open the event viewer.
This issue has been resolved in Symantec™ Embedded Security: Critical System Protection release 1.0.1.