I don't think so, since restarting services is an OS-level event rather than an application level event.
You'd have to have security auditing configured on Windows & check the Security Event Log to see who connected around the time the services were restarted.
MARCUS. Why dost thou laugh? It fits not with this hour.
TITUS. Why, I have not another tear to shed;
--Titus Andronicus, William Shakespeare