1. You will need the Splunk alert to check for failed/stopped services and send an alert through to Phantom with the service name/other information to help the script/command, such as the hostname etc. 2. Build a playbook against the label that these events come in as that will use the information in the event to build the command or provide necessary arguments to the script and run the action(s).
I have not used the above app myself but looking through the docs, it looks like it will provide the capability you require. Also take a look through the community playbooks and see if there is any examples that are similar to your use case.