If you are comfortable change transforms.conf & props.conf , you will need to add a field extraction rule to extract these fields at searchtime. Something like this in your transforms should do it
[your stanza]
REGEX = ([^:]+):(.*)
FORMAT = $1::$2
The other option is to achieve this from web ui (this may be easier with similar results). Here's a link on that http://docs.splunk.com/Documentation/Splunk/6.2.0/Knowledge/Managefieldtransforms
Third option, is use the extract command in your search, like this
... | extract pairdelim="\n" kvdelim=":"
This would be my last option.
... View more