'How do we use Kusto Query Language to capture windows service restart?

How do we use Kusto Query Language to capture windows service restart (event id 1074)? Along with Account Name, Account Domain, and Process name. Which log(s) should we use?

kql


Sources

This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.

Source: Stack Overflow

Solution Source