<a href="https://colab.research.google.com/github/harnalashok/hadoop/blob/main/colab_and_pyspark.ipynb" target="_parent"><img src="https://colab.research.google.com/assets/colab-badge.svg" alt="Open In Colab"/></a>

In [None]:
# Last amended: 14th July, 2024

Reference [here](https://colab.research.google.com/drive/1G894WS7ltIUTusWWmsCnF_zQhQqZCDOc)

References:    
1. [This page](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/index.html#) gives an overview of all public Spark SQL API.     
2. Functions: [All functions](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/functions.html#) available for DataFrame operations    
3. [This page](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.DataFrame.html) gives all DataFrame methods    
4. pyspark [by examples](https://sparkbyexamples.com/pyspark-tutorial/)     
5. MLlib main [examples](https://spark.apache.org/docs/latest/ml-guide.html)     

<h1><center>Introduction to Google Colab and PySpark</center></h1>

## Table Of Contents:
<ol>
<li><a href="#objective">Objective</a></li>
<li><a href="#prerequisite">Prerequisite</a></li>
<li><a href="#notes-from-the-author">Notes from the Author</a></li>
<li><a href="#big-data-pyspark-and-colaboratory">Big data, PySpark and Colaboratory</a>
    <ol>
        <li><a href="#big-data">Big data</a></li>
        <li><a href="#pyspark">PySpark</a></li>
        <li><a href="#colaboratory">Colaboratory</a></li>
    </ol>
</li>
<li><a href="#jupyter-notebook-basics">Jupyter Notebook Basics</a>
    <ol>
        <li><a href="#code-cells">Code cells</a></li>
        <li><a href="#text-cells">Text cells</a></li>
        <li><a href="#access-to-the-shell">Access to the shell</a></li>
        <li><a href="#installing-spark">Installing Spark</a></li>
    </ol>
</li>
<li><a href="#exploring-the-dataset">Exploring the Dataset</a>
    <ol>
        <li><a href="#loading-the-dataset">Loading the Dataset</a></li>
        <li><a href="#viewing-the-dataframe">Viewing the Dataframe</a></li>
        <li><a href="#viewing-dataframe-columns">Viewing Dataframe Columns</a></li>
        <li><a href="#dataframe-schema">Dataframe Schema</a>
          <ul>
            <li><a href="#implicit-schema-inference">Inferring Schema Implicitly</a></li>
            <li><a href="#explicit-schema-inference">Defining Schema Explicitly</a></li>
          </ul>
        </li>
    </ol>
</li>
<li><a href="#dataframe-operations-on-columns">DataFrame Operations on Columns</a>
    <ol>
        <li><a href="#selecting-columns">Selecting Columns</a></li>
        <li><a href="#selecting-multiple-columns">Selecting Multiple Columns</a></li>
        <li><a href="#adding-new-columns">Adding New Columns</a></li>
        <li><a href="#renaming-columns">Renaming Columns</a>
        <li><a href="#grouping-by-columns">Grouping By Columns</a>
        <li><a href="#removing-columns">Removing Columns</a>
    </ol>
</li>
<li><a href="#dataframe-operations-on-rows">DataFrame Operations on Rows</a>
    <ol>
        <li><a href="#filtering-rows">Filtering Rows</a></li>
        <li><a href="#get-distinct-rows">Get Distinct Rows</a></li>
        <li><a href="#sorting-rows">Sorting Rows</a></li>
        <li><a href="#union-dataframes">Union Dataframes</a>
    </ol>
</li>
<li><a href="#common-data-manipulation-functions">Common Data Manipulation Functions</a>
    <ol>
        <li><a href="#string-functions">String Functions</a></li>
        <li><a href="#numeric-functions">Numeric Functions</a></li>
        <li><a href="#operations-on-date">Operations on Date</a></li>
    </ol>
</li>
<li><a href="#joins-in-pyspark">Joins in PySpark</a></li>
<li><a href="#spark-sql">Spark SQL</a></li>
<li><a href="#rdd">RDD</a></li>
<li><a href="#user-defined-functions-udf">User-Defined Functions (UDF)</a></li>
<li><a href="#common-questions">Common Questions</a>
    <ol>
        <li><a href="#recommended-ide">Recommended IDE</a></li>
        <li><a href="#submitting-a-spark-job">Submitting a Spark Job</a></li>
        <li><a href="#creating-dataframes">Creating Dataframes</a></li>
        <li><a href="#drop-duplicates">Drop Duplicates</a></li>
        <li><a href="#fine-tuning-a-pyspark-job">Fine Tuning a PySpark Job</a>
          <ul>
            <li><a href="#emr-sizing">EMR Sizing</a></li>
            <li><a href="#spark-configurations">Spark Configurations</a></li>
            <li><a href="#job-tuning">Job Tuning</a>
            <li><a href="#best-practices">Best Practices</a>
          </ul>
        </li>
    </ol>
</li>
</ol>

<a id='objective'></a>
## Objective
The objective of this notebook is to:
><li>Give a proper understanding about the different PySpark functions available. </li>
><li>A short introduction to Google Colab, as that is the platform on which this notebook is written on. </li>

Once you complete this notebook, you should be able to write pyspark programs in an efficent way. The ideal way to use this is by going through the examples given and then trying them on Colab. At the end there are a few hands on questions which you can use to evaluate yourself.

<a id='prerequisite'></a>
## Prerequisite
><li>Although some theory about pyspark and big data will be given in this notebook, I recommend everyone to read more about it and have a deeper understanding on how the functions get executed and the relevance of big data in the current scenario.
><li>A good understanding on python will be an added bonus.

<a id='notes-from-the-author'></a>
## Notes from the Author

This tutorial was made using Google Colab so the code you see here is meant to run on a colab notebook. <br>
It goes through basic [PySpark Functions](https://spark.apache.org/docs/latest/api/python/index.html). <br>

If you want to view the author's original colab notebook for this particular tutorial, you can view it [here](https://colab.research.google.com/drive/1G894WS7ltIUTusWWmsCnF_zQhQqZCDOc). The viewing experience and readability is much better there. <br>

<a id='big-data and pyspark'></a>
## Big data and PySpark

<a id='big-data'></a>
### Big data

Big data usually means data of such huge volume that normal data storage solutions cannot efficently store and process it. In this era, data is being generated at an absurd rate. Data is collected for each movement a person makes. The bulk of big data comes from three primary sources:
<ol>
   <li>Social data</li>
   <li>Machine data</li>
   <li>Transactional data</li>
</ol>

Some common examples for the sources of such data include internet searches, facebook posts, doorbell cams, smartwatches, online shopping history etc. Every action creates data, it is just a matter of of there is a way to collect them or not.  But what's interesting is that out of all this data collected, not even 5% of it is being used fully. There is a huge demand for big data professionals in the industry. Even though the number of graduates with a specialization in big data are rising, the problem is that they don't have the practical knowledge about big data scenarios, which leads to bad architecutres and inefficent methods of processing data.

>If you are interested to know more about the landscape and technologies involved, here is [an article](https://hostingtribunal.com/blog/big-data-stats/) which I found really interesting!

<a id='pyspark'></a>
### PySpark

If you are working in the field of big data, you must have definelty heard of spark. If you look at the [Apache Spark](https://spark.apache.org/) website, you will see that it is said to be a `Lightning-fast unified analytics engine`. PySpark is a flavour of Spark used for processing and analysing massive volumes of data. If you are familiar with python and have tried it for huge datasets, you should know that the execution time can get ridiculous. Enter PySpark!

Imagine your data resides in a distributed manner at different places. If you try brining your data to one point and executing your code there, not only would that be inefficent, but also cause memory issues. Now let's say your code goes to the data rather than the data coming to where your code. This will help avoid unneccesary data movement which will thereby decrease the running time.

PySpark is the Python API of Spark; which means it can do almost all the things python can. Machine learning(ML) pipelines, exploratory data analysis (at scale), ETLs for data platform, and much more! And all of them in a distributed manner. One of the best parts of pyspark is that if you are already familiar with python, it's really easy to learn.

Apart from PySpark, there is another language called Scala used for big data processing. Scala is frequently over 10 times faster than *Python*, as it is native for Hadoop as its based on JVM. But PySpark is getting adopted at a fast rate because of the ease of use, easier learning curve and ML capabilities.

I will briefly explain how a PySpark job works, but I strongly recommend you read more about the [architecture](https://data-flair.training/blogs/how-apache-spark-works/) and how everything works. Now, before I get into it, let me talk about some <u>basic jargons</u> first:

<b>Cluster</b> is a set of loosely or tightly connected computers that work together so that they can be viewed as a single system.

<b>Hadoop</b> is an open source, scalable, and fault tolerant framework written in Java. It efficiently processes large volumes of data on a cluster of commodity hardware. Hadoop is not only a storage system but is a platform for large data storage as well as processing.

<b>HDFS</b> (Hadoop distributed file system). It is one of the world's most reliable storage system. HDFS is a Filesystem of Hadoop designed for storing very large files running on a cluster of commodity hardware.

<b>MapReduce</b> is a data Processing framework, which has 2 phases - Mapper and Reducer. The map procedure performs filtering and sorting, and the reduce method performs a summary operation. It usually runs on a hadoop cluster.

<b>Transformation</b> refers to the operations applied on a dataset to create a new dataset. Filter, groupBy and map are the examples of transformations.

<b>Actions</b> Actions refer to an operation which instructs Spark to perform computation and send the result back to driver. This is an example of action.

Alright! Now that that's out of the way, let me explain how a spark job runs. In simple terma, each time you submit a pyspark job, the code gets internally converted into a MapReduce program and gets executed in the Java virtual machine. Now one of the thoughts that might be popping in your mind will probably be: <br>`So the code gets converted into a MapReduce program. Wouldn't that mean MapReduce is faster than pySpark?`<br> Well, the answer is a big NO. This is what makes spark jobs special. Spark is capable of handling a massive amount of data at a time, in it's distributed environment. It does this through <u>in-memory processing</u>, which is what makes it almost 100 times faster than Hadoop. Another factor which amkes it fast is <u>Lazy Evaluation</u>. Spark delays its evaluation as much as it can. Each time you  submit a job, spark creates an action plan for how to execute the code, and then does nothing. Finally, when you ask for the result(i.e, calls an action), it executes the plan, which is basically all the transofrmations you have mentioned in your code. That's basically the gist of it.

Now lastly, I want to talk about on more thing. Spark mainly consists of 4 modules:

<ol>
    <li>Spark SQL - helps to write  spark programs using SQL like queries.</li>
    <li>Spark Streaming - is an extension of the core Spark API that enables scalable, high-throughput, fault-tolerant stream processing of live data streams. used heavily in processing of social media data.</li>
    <li>Spark MLLib - is the machine learning component of SPark. It helps train ML models on massive datasets with very high efficeny. </li>
    <li>Spark GraphX - is the visualization component of Spark. It enables users to view data both as graphs and as collections without data movement or duplication.</li>
</ol>



<a id='installing-spark'></a>
## Installing Spark

Install Dependencies:


1.   Java 8
2.   Apache Spark with hadoop and
3.   Findspark (used to locate the spark in the system)

> If you have issues with spark version, please upgrade to the latest version from [here](https://archive.apache.org/dist/spark/).

In [None]:
from IPython.core.interactiveshell import InteractiveShell
InteractiveShell.ast_node_interactivity = "all"


In [None]:
%%shell

# Ref: https://stackoverflow.com/a/59839
export DIRECTORY="/content/spark-3.5.1-bin-hadoop3"
if [ -d "$DIRECTORY" ]; then
  rm -r -f /content/spark-3.5.1-bin-hadoop3
  rm /content/spark-3.5.1-bin-hadoop3.tgz
  echo "Folder $DIRECTORY removed"
else
  echo "No such folder $DIRECTORY "
fi

No such folder /content/spark-3.5.1-bin-hadoop3 




Offlate there have been problems with downloading spark. Better run the code in VM.

In [None]:
%%time

# Every command in quiet mode (-q or /dev/null or no -v flag)
# Repeated execution may download multiple files, creating problems

! apt-get install openjdk-8-jdk-headless -qq > /dev/null
print("*Installed openjdk*")
! wget -q http://archive.apache.org/dist/spark/spark-3.5.1/spark-3.5.1-bin-hadoop3.tgz
print("*Downloaded Apache Spark*")
! tar xf spark-3.5.1-bin-hadoop3.tgz
print("*Untarred Apache Spark*")
! pip install -q findspark
print("*Installed findspark*")
print("*"*20)

*Installed openjdk*
*Downloaded Apache Spark*
*Untarred Apache Spark*
*Installed findspark*
********************
CPU times: user 446 ms, sys: 51.3 ms, total: 498 ms
Wall time: 1min 5s


OR, to avoid inadvertent repeated execution, execute individually:

## Set Environment Variables:
And start spark session

In [None]:
# Set standard environmental variables:

import os
os.environ["JAVA_HOME"] = "/usr/lib/jvm/java-8-openjdk-amd64"
os.environ["SPARK_HOME"] = "/content/spark-3.5.1-bin-hadoop3"

In [None]:
%%time

# Install findspark and create Spark Session

import findspark
findspark.init()

from pyspark.sql import SparkSession

spark = SparkSession.builder.master("local[*]").getOrCreate()
spark.conf.set("spark.sql.repl.eagerEval.enabled", True) # Property used to format output tables better
spark

CPU times: user 556 ms, sys: 52.4 ms, total: 608 ms
Wall time: 9.73 s


In [None]:
# For creating first pandas dataframe
#  and then transforming to spark dataframes
import pandas as pd
import numpy as np

<a id='loading-the-dataset'></a>
## Loading the Dataset

In [None]:
# Downloading and preprocessing Cars Data downloaded origianlly
#  from https://perso.telecom-paristech.fr/eagan/class/igr204/datasets

!wget https://jacobceles.github.io/knowledge_repo/colab_and_pyspark/cars.csv

--2024-07-13 05:04:11--  https://jacobceles.github.io/knowledge_repo/colab_and_pyspark/cars.csv
Resolving jacobceles.github.io (jacobceles.github.io)... 185.199.108.153, 185.199.109.153, 185.199.110.153, ...
Connecting to jacobceles.github.io (jacobceles.github.io)|185.199.108.153|:443... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: https://jacobcelestine.com/knowledge_repo/colab_and_pyspark/cars.csv [following]
--2024-07-13 05:04:12--  https://jacobcelestine.com/knowledge_repo/colab_and_pyspark/cars.csv
Resolving jacobcelestine.com (jacobcelestine.com)... 185.199.108.153, 185.199.109.153, 185.199.110.153, ...
Connecting to jacobcelestine.com (jacobcelestine.com)|185.199.108.153|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 22608 (22K) [text/csv]
Saving to: ‘cars.csv’


2024-07-13 05:04:12 (24.8 MB/s) - ‘cars.csv’ saved [22608/22608]



API for `spark.read.csv` is [here](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.DataFrameReader.csv.html)

In [None]:
%%time

# Load data from csv to a dataframe.
# header=True means the first row is a header
# sep=';' means the column are seperated using ''

df = spark.read.csv('cars.csv',
                    header=True,  # Defalut: None (c0, c1 etc will be header)
                    sep=";"       # Default: None (only one column exists)
                    )

# Same as df.head(5) in pandas
df.show(5)

+--------------------+----+---------+------------+----------+------+------------+-----+------+
|                 Car| MPG|Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|
+--------------------+----+---------+------------+----------+------+------------+-----+------+
|Chevrolet Chevell...|18.0|        8|       307.0|     130.0| 3504.|        12.0|   70|    US|
|   Buick Skylark 320|15.0|        8|       350.0|     165.0| 3693.|        11.5|   70|    US|
|  Plymouth Satellite|18.0|        8|       318.0|     150.0| 3436.|        11.0|   70|    US|
|       AMC Rebel SST|16.0|        8|       304.0|     150.0| 3433.|        12.0|   70|    US|
|         Ford Torino|17.0|        8|       302.0|     140.0| 3449.|        10.5|   70|    US|
+--------------------+----+---------+------------+----------+------+------------+-----+------+
only showing top 5 rows

CPU times: user 59.1 ms, sys: 2.18 ms, total: 61.3 ms
Wall time: 9.7 s


The above command loads our data from into a dataframe (DF). A dataframe is a 2-dimensional labeled data structure with columns of potentially different types.

<a id='viewing-the-dataframe'></a>
## Viewing the Dataframe

There are a couple of ways to view your dataframe(DF) in PySpark:

1.   `df.take(5)` will return a list of five Row objects.
2.   `df.collect()` will get all of the data from the entire DataFrame. Be really careful when using it, because if you have a large data set, you can easily crash the driver node.
3.   `df.show()` is the most commonly used method to view a dataframe. There are a few parameters we can pass to this method, like the number of rows and truncaiton. For example, `df.show(5, False)` or ` df.show(5, truncate=False)` will show the entire data wihtout any truncation.
4.   `df.limit(5)` will **return a new DataFrame** by taking the first n rows. As spark is distributed in nature, there is no guarantee that `df.limit()` will give you the same results each time.

Let us see some of them in action below:

In [None]:
%%time

# Each column gets full length:
df.show(5, truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504. |12.0        |70   |US    |
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693. |11.5        |70   |US    |
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436. |11.0        |70   |US    |
|AMC Rebel SST            |16.0|8        |304.0       |150.0     |3433. |12.0        |70   |US    |
|Ford Torino              |17.0|8        |302.0       |140.0     |3449. |10.5        |70   |US    |
+-------------------------+----+---------+------------+----------+------+------------+-----+------+
only showing top 5 rows

CPU times: user 1.29 ms, sys: 0 ns, total: 1.29 ms
Wall time: 257 ms


In [None]:
%%time

# A new dataframe but truncated display
df.limit(5)

CPU times: user 4.69 ms, sys: 0 ns, total: 4.69 ms
Wall time: 16.1 ms


Car,MPG,Cylinders,Displacement,Horsepower,Weight,Acceleration,Model,Origin
Chevrolet Chevell...,18.0,8,307.0,130.0,3504.0,12.0,70,US
Buick Skylark 320,15.0,8,350.0,165.0,3693.0,11.5,70,US
Plymouth Satellite,18.0,8,318.0,150.0,3436.0,11.0,70,US
AMC Rebel SST,16.0,8,304.0,150.0,3433.0,12.0,70,US
Ford Torino,17.0,8,302.0,140.0,3449.0,10.5,70,US


<a id='viewing-dataframe-columns'></a>
### Viewing Dataframe Columns

In [None]:
df.columns


['Car',
 'MPG',
 'Cylinders',
 'Displacement',
 'Horsepower',
 'Weight',
 'Acceleration',
 'Model',
 'Origin']

In [None]:
# df.shape       # This does not exist
len(df.columns)  # No of columns
print("*"*20)
df.describe() # Data stats
print("*"*20)
df.count()    # No of rows

9

********************


summary,Car,MPG,Cylinders,Displacement,Horsepower,Weight,Acceleration,Model,Origin
count,406,406.0,406.0,406.0,406.0,406.0,406.0,406.0,406
mean,,23.0512315270936,5.475369458128079,194.7795566502463,103.5295566502463,2979.4137931034484,15.51970443349752,75.92118226600985,
stddev,,8.4017773522706,1.712159631548529,104.92245837948867,40.52065912106347,847.0043282393513,2.8033588163425462,3.7487373454558734,
min,AMC Ambassador Br...,0.0,3.0,100.0,0.0,1613.0,10.0,70.0,Europe
max,Volvo Diesel,9.0,8.0,98.0,98.0,5140.0,9.5,82.0,US


********************


406

<a id='dataframe-schema'></a>
### Dataframe Schema

There are two methods commonly used to view the data types of a dataframe:

In [None]:
df.dtypes

[('Car', 'string'),
 ('MPG', 'string'),
 ('Cylinders', 'string'),
 ('Displacement', 'string'),
 ('Horsepower', 'string'),
 ('Weight', 'string'),
 ('Acceleration', 'string'),
 ('Model', 'string'),
 ('Origin', 'string')]

In [None]:
df.printSchema()

root
 |-- Car: string (nullable = true)
 |-- MPG: string (nullable = true)
 |-- Cylinders: string (nullable = true)
 |-- Displacement: string (nullable = true)
 |-- Horsepower: string (nullable = true)
 |-- Weight: string (nullable = true)
 |-- Acceleration: string (nullable = true)
 |-- Model: string (nullable = true)
 |-- Origin: string (nullable = true)



<a id='implicit-schema-inference'></a>
#### Inferring Schema Implicitly

We can use the parameter `inferschema=true` to infer the input schema automatically while loading the data.    

But then spark reads ENTIRE data once. An example is shown below:

In [None]:
%%time

df = spark.read.csv('cars.csv',
                    header=True,
                    sep=";",
                    inferSchema=True  #  Go through entire data once
                                      #  to determine the input schema
                    )

df.printSchema()

root
 |-- Car: string (nullable = true)
 |-- MPG: double (nullable = true)
 |-- Cylinders: integer (nullable = true)
 |-- Displacement: double (nullable = true)
 |-- Horsepower: double (nullable = true)
 |-- Weight: decimal(4,0) (nullable = true)
 |-- Acceleration: double (nullable = true)
 |-- Model: integer (nullable = true)
 |-- Origin: string (nullable = true)

CPU times: user 11.6 ms, sys: 1.94 ms, total: 13.6 ms
Wall time: 1.12 s


As you can see, the datatype has been infered automatically spark with even the correct precison for decimal type. A problem that might arise here is that sometimes, when you have to read multiple files with different schemas in different files, there might be an issue with implicit inferring leading to null values in some columns. We can also define schemas explicitly.

<a id='dataframe-operations-on-columns'></a>
## DataFrame Operations on Columns

We will go over the following in this section:

1.   Select columns
2.   Select multiple columns: `select('a',df.b,df['c'],col('d'))`
3.   Add new columns either as a derived column or as a constant column: `df.withColumn('newCol', df.MPG+2)` OR as `df.withColumn('newCol', lit('US'))`
4.   Rename Columns: `df.withColumnRenamed('oldName', 'newName'))`
5.   Grouping By Columns: `df.groupby(df.Car,"Origin").agg({"Weight": "sum"})`
6.   Remove Columns: `df.drop('new_column_one')`



<a id='selecting-columns'></a>
### Selecting Columns

There are multiple ways to do a select in PySpark. You can find how they differ and how each below:

In [None]:
from pyspark.sql.functions import col

In [None]:
%%time

# 1st method: Dot notation
# Column name is case sensitive in dot notation
print(df.Car)     # Just tells column

print("*"*20)     # 20 stars

print(df.Cylinders + 2)     # Just tells column

print("*"*20)     # 20 stars

df.select(df.Cylinders).show(3,truncate=False)

print("*"*20)     # 20 stars

df.select(df.Cylinders + 2).show(3,truncate=False)


Column<'Car'>
********************
Column<'(Cylinders + 2)'>
********************
+---------+
|Cylinders|
+---------+
|8        |
|8        |
|8        |
+---------+
only showing top 3 rows

********************
+---------------+
|(Cylinders + 2)|
+---------------+
|10             |
|10             |
|10             |
+---------------+
only showing top 3 rows

CPU times: user 13.4 ms, sys: 3.3 ms, total: 16.7 ms
Wall time: 349 ms


**NOTE:**

> What is we our dataset has two columns with names as `sql` and `columns`. Then `df.sql` or `df.columns` (like `df.Car`) will have ambiguous meanings.    

>We can't always use the dot notation because this will break when the column names are same as **reserved names (for example, `sql`)** or attributes to the data frame class (for example, `columns`).   

>Additionally, the column names are case sensitive in nature so we need to always make sure the column names have been changed to a paticular case before using it.



In [None]:
%%time

# 2nd method instead of dot notation use df['car']
# Column name is case insensitive here
print(df['car'])   # df['car'] stands for column object
print("*"*20)
df.select(df['car']).show(3,truncate=False)

Column<'car'>
********************
+-------------------------+
|car                      |
+-------------------------+
|Chevrolet Chevelle Malibu|
|Buick Skylark 320        |
|Plymouth Satellite       |
+-------------------------+
only showing top 3 rows

CPU times: user 5.7 ms, sys: 73 µs, total: 5.78 ms
Wall time: 182 ms


`col()` function. See its [API here](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.functions.col.html)

In [None]:
%%time

# 3rd method
# Column name is case insensitive here

df.select(col('car')).show(3,truncate=False)  # col('car') is also column object

+-------------------------+
|car                      |
+-------------------------+
|Chevrolet Chevelle Malibu|
|Buick Skylark 320        |
|Plymouth Satellite       |
+-------------------------+
only showing top 3 rows

CPU times: user 3.21 ms, sys: 1.14 ms, total: 4.35 ms
Wall time: 141 ms


<a id='selecting-multiple-columns'></a>
### Selecting Multiple Columns

In [None]:
# Column objects:
df.Car
df['Car']
col('Car')

Column<'Car'>

In [None]:
# All methods using select statement
# Column name is case sensitive in this usage
print(df.Car, df.Cylinders)
print("*"*40)
df.select(df.Car, df.Cylinders).show(3, truncate=False)         # case sensitive
df.select(df['car'], df['Cylinders']).show(3, truncate=False)   # case insensitive
df.select(col('car'), col('Cylinders')).show(3, truncate=False) # case insensitive
# A short-cut in select statement:
df.select("car", "cylinders").show(3, truncate=False)           # case insensitive

# A list of columns is also permitted:
df.select(["car", "cylinders"]).show(3)

Column<'Car'> Column<'Cylinders'>
****************************************
+-------------------------+---------+
|Car                      |Cylinders|
+-------------------------+---------+
|Chevrolet Chevelle Malibu|8        |
|Buick Skylark 320        |8        |
|Plymouth Satellite       |8        |
+-------------------------+---------+
only showing top 3 rows

+-------------------------+---------+
|car                      |Cylinders|
+-------------------------+---------+
|Chevrolet Chevelle Malibu|8        |
|Buick Skylark 320        |8        |
|Plymouth Satellite       |8        |
+-------------------------+---------+
only showing top 3 rows

+-------------------------+---------+
|car                      |Cylinders|
+-------------------------+---------+
|Chevrolet Chevelle Malibu|8        |
|Buick Skylark 320        |8        |
|Plymouth Satellite       |8        |
+-------------------------+---------+
only showing top 3 rows

+-------------------------+---------+
|car          

<a id='adding-new-columns'></a>
### Adding New Columns

Syntax:  Returns a new DataFrame by adding a column or replacing the existing column that has the same name.     
`df.withColumn(colName: str, col: column object)` <br>
Example: `df.withColumn('age2', df.age + 2).show()`

We will take a look at three cases here:

1.   Adding a new column
2.   Adding multiple columns
3.   Deriving a new column from an exisitng one

In [None]:
# CASE 1: Adding a new column
# We will add a new column called 'first_column' at the end
from pyspark.sql.functions import lit

# A column must be added with a literal value
#  creating a column with null values is not permitted:

df = df.withColumn('first_column',lit('USA'))

# lit means literal. It populates the row with the literal value given.
# When adding static data / constant values, it is a good practice to use it.

df.show(3,truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+------------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|first_column|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+------------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504  |12.0        |70   |US    |USA         |
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693  |11.5        |70   |US    |USA         |
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436  |11.0        |70   |US    |USA         |
+-------------------------+----+---------+------------+----------+------+------------+-----+------+------------+
only showing top 3 rows



In [None]:
# CASE 2: Adding multiple columns
#         Repeated dot notations
# We will add two new columns called 'second_column' and 'third_column' at the end:
df = df.withColumn('second_column', lit(2)) \
       .withColumn('third_column', lit('Third Column'))

# lit means literal. It populates the row with the literal value given.
# When adding static data / constant values, it is a good practice to use it.
df.show(3,truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+------------+-------------+------------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|first_column|second_column|third_column|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+------------+-------------+------------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504  |12.0        |70   |US    |USA         |2            |Third Column|
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693  |11.5        |70   |US    |USA         |2            |Third Column|
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436  |11.0        |70   |US    |USA         |2            |Third Column|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+------------+-------------+------------+
only showing top 3 r

<a id='renaming-columns'></a>
### Renaming Columns

We use the `withColumnRenamed` function to rename a columm in PySpark. Let us see it in action below:    
Syntax:  `df.withColumnRenamed(existing: str, new: str)`

In [None]:
# Renaming a column in PySpark
df = df.withColumnRenamed('first_column', 'new_column_one') \
       .withColumnRenamed('second_column', 'new_column_two') \
       .withColumnRenamed('third_column', 'new_column_three')

df.show(3,truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+--------------+--------------+----------------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|new_column_one|new_column_two|new_column_three|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+--------------+--------------+----------------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504  |12.0        |70   |US    |USA           |2             |Third Column    |
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693  |11.5        |70   |US    |USA           |2             |Third Column    |
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436  |11.0        |70   |US    |USA           |2             |Third Column    |
+-------------------------+----+---------+------------+----------+------+------------+-----+------+--------------+----

<a id='grouping-by-columns'></a>
## Grouping By Columns

Here, we see the Dataframe API way of grouping values. We will discuss how to:


1.   Group By a single column: `groupby` and `groupBy` are same
2.   Group By multiple columns
3.  Available summary functions are [here](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.GroupedData.html#pyspark.sql.GroupedData)

`df.groupby(df.Car,"Origin", df['Model'], col("Cylinders")).agg({"Weight": "sum", "Car" : "count", "MPG" : 'mean'})`

Aggregators are: count(), sum(), max(), min(), mean(), avg(), sum()   

Please see [here](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.GroupedData.html#pyspark.sql.GroupedData)

In [None]:
# Needed if you use these functions
# and not 'mean', 'avg', 'sum' etc in .agg()
from pyspark.sql.functions import avg, sum, count

In [None]:
# Group By a column in PySpark:

df.groupBy('Origin').count().show(5)

+------+-----+
|Origin|count|
+------+-----+
|Europe|   73|
|    US|  254|
| Japan|   79|
+------+-----+



In [None]:
# Group By multiple columns in PySpark
df.groupBy('Origin', 'Model').count().show(5)

# A list of columns will also be OK
df.groupBy(['Origin', 'Model']).count().show(5)

+------+-----+-----+
|Origin|Model|count|
+------+-----+-----+
| Japan|   76|    4|
|    US|   81|   13|
|    US|   80|    7|
|    US|   76|   22|
| Japan|   70|    2|
+------+-----+-----+
only showing top 5 rows

+------+-----+-----+
|Origin|Model|count|
+------+-----+-----+
| Japan|   76|    4|
|    US|   81|   13|
|    US|   80|    7|
|    US|   76|   22|
| Japan|   70|    2|
+------+-----+-----+
only showing top 5 rows



In [None]:
# Multiple columns and general form of aggregation:

df.groupby(df.Car,"Origin", df['Model'], col("Cylinders")). \
agg({"Weight": "sum", "Car" : "count", "MPG" : 'mean'}).show(3)

+--------------------+------+-----+---------+----------+--------+-----------+
|                 Car|Origin|Model|Cylinders|count(Car)|avg(MPG)|sum(Weight)|
+--------------------+------+-----+---------+----------+--------+-----------+
|Buick Century Lux...|    US|   74|        8|         1|    13.0|       4699|
|      Toyota Corolla| Japan|   75|        4|         2|    26.5|       4873|
|Oldsmobile Cutlas...|    US|   77|        8|         1|    17.0|       4060|
+--------------------+------+-----+---------+----------+--------+-----------+
only showing top 3 rows



<a id='removing-columns'></a>
## Remove/Drop Columns

In [None]:
#Remove columns in PySpark
df = df.drop('new_column_one')
df.show(5,truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+--------------+----------------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|new_column_two|new_column_three|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+--------------+----------------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504  |12.0        |70   |US    |2             |Third Column    |
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693  |11.5        |70   |US    |2             |Third Column    |
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436  |11.0        |70   |US    |2             |Third Column    |
|AMC Rebel SST            |16.0|8        |304.0       |150.0     |3433  |12.0        |70   |US    |2             |Third Column    |
|Ford Torino              |17.0|8        |302.0       |140.0     |3449  |10.

In [None]:
#Remove columns in PySpark
df = df.drop(df.new_column_two)
df.show(5,truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+----------------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|new_column_three|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+----------------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504  |12.0        |70   |US    |Third Column    |
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693  |11.5        |70   |US    |Third Column    |
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436  |11.0        |70   |US    |Third Column    |
|AMC Rebel SST            |16.0|8        |304.0       |150.0     |3433  |12.0        |70   |US    |Third Column    |
|Ford Torino              |17.0|8        |302.0       |140.0     |3449  |10.5        |70   |US    |Third Column    |
+-------------------------+----+---------+------------+---------

In [None]:
#Remove columns in PySpark
df = df.drop(col("new_column_three"))
df.show(5,truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504  |12.0        |70   |US    |
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693  |11.5        |70   |US    |
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436  |11.0        |70   |US    |
|AMC Rebel SST            |16.0|8        |304.0       |150.0     |3433  |12.0        |70   |US    |
|Ford Torino              |17.0|8        |302.0       |140.0     |3449  |10.5        |70   |US    |
+-------------------------+----+---------+------------+----------+------+------------+-----+------+
only showing top 5 rows



In [None]:
#Remove multiple columnss in one go
# Repeated drops:

df = df.drop('new_column_two') \
       .drop('new_column_three')
df.show(5,truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+----------------------------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|car_model                   |
+-------------------------+----+---------+------------+----------+------+------------+-----+------+----------------------------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504.0|12.0        |70   |US    |Chevrolet Chevelle Malibu 70|
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693.0|11.5        |70   |US    |Buick Skylark 320 70        |
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436.0|11.0        |70   |US    |Plymouth Satellite 70       |
|AMC Rebel SST            |16.0|8        |304.0       |150.0     |3433.0|12.0        |70   |US    |AMC Rebel SST 70            |
|Ford Torino              |17.0|8        |302.0       |140.0     |3449.0|10.5        |70   |US   

<a id='dataframe-operations-on-rows'></a>
## DataFrame Operations on Rows

We will discuss the follwoing in this section:

1.   Filtering Rows: `df.filter((col('Origin')=='Europe') & (df.Cylinders == 4))`
2. 	 Get Distinct Rows: `df.select('a').distinct()`
3.   Sorting Rows: `df.orderBy("Cylinders", df.Cylinders, df['Cylinders'], col("Cylinders"))`  
4.   Union Dataframes

`where(cond)` is an alias for `filter(cond)`

See syntax of `filter` [here](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/api/pyspark.sql.DataFrame.filter.html#pyspark.sql.DataFrame.filter)  

<a id='filtering-rows'></a>
### Filtering Rows

In [None]:
from pyspark.sql.functions import col

df.count()
print()
df.filter(col('Origin') == 'Europe').count()
print()
df.filter(df['Origin'] == 'Europe').count()
print()
df.filter(df.Origin == 'Europe').count()
print()
df.filter(df.Origin == 'Europe').show(3)




406




73




73




73


+--------------------+----+---------+------------+----------+------+------------+-----+------+
|                 Car| MPG|Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|
+--------------------+----+---------+------------+----------+------+------------+-----+------+
|Citroen DS-21 Pallas| 0.0|        4|       133.0|     115.0|  3090|        17.5|   70|Europe|
|Volkswagen 1131 D...|26.0|        4|        97.0|      46.0|  1835|        20.5|   70|Europe|
|         Peugeot 504|25.0|        4|       110.0|      87.0|  2672|        17.5|   70|Europe|
+--------------------+----+---------+------------+----------+------+------------+-----+------+
only showing top 3 rows



In [None]:
# Using and (&) or (|) operators:

df.filter((col('Origin')=='Europe') & (df.Cylinders == 4)).count()

66

<a id='get-distinct-rows'></a>
## Get Distinct Rows
Use `distinct()`

In [None]:
#Get Unique Rows in PySpark
df.select('Origin').distinct().show()

+------+
|Origin|
+------+
|Europe|
|    US|
| Japan|
+------+



In [None]:
# Get Unique Rows in PySpark based on mutliple columns
df.select('Origin','model').distinct().show(3)

+------+-----+
|Origin|model|
+------+-----+
|Europe|   71|
|Europe|   80|
|Europe|   79|
+------+-----+
only showing top 3 rows



## Drop duplicate rows
There are two easy to remove duplicates from a dataframe. We have already seen the usage of distinct under section.     

We can also use the `dropDuplicates()` function to achieve the same.

> `drop_duplicates()` is an alias for `dropDuplicates()`

In [None]:
# Create a pandas Daraframe with duplicate rows:
import pandas as pd
dfp = pd.DataFrame.from_records([
                                  ['alice', 32, 5.1],
                                  ['jone', 33, 4.8],
                                  ['alice', 32, 5.1]
                                 ],
                                 columns = ['name', 'age', 'height']
                                )

dfp.head()


Unnamed: 0,name,age,height
0,alice,32,5.1
1,jone,33,4.8
2,alice,32,5.1


name,age,height
alice,32,5.1
jone,33,4.8
alice,32,5.1


In [None]:
# Transform pandas to spark dataframe:

dfd = spark.createDataFrame(dfp)

In [None]:
# Drop duplicates:

dfd.dropDuplicates().show()

+-----+---+------+
| name|age|height|
+-----+---+------+
|alice| 32|   5.1|
| jone| 33|   4.8|
+-----+---+------+



<a id='sorting-rows'></a>
## Sorting Rows
`df.orderBy("Cylinders", df.Cylinders, df['Cylinders'], col("Cylinders"))`      
`df.orderBy("Cylinders", df.Cylinders, df['Cylinders'], col("Cylinders"), ascending = False)`

In [None]:
# Sort Rows in PySpark
# By default the data will be sorted in ascending order

df.orderBy('Cylinders').show(5,truncate=False)  # Default: ascending = True

+----------------------------+----+---------+------------+----------+------+------------+-----+------+
|Car                         |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|
+----------------------------+----+---------+------------+----------+------+------------+-----+------+
|Mazda RX2 Coupe             |19.0|3        |70.00       |97.00     |2330. |13.5        |72   |Japan |
|Mazda RX3                   |18.0|3        |70.00       |90.00     |2124. |13.5        |73   |Japan |
|Mazda RX-4                  |21.5|3        |80.00       |110.0     |2720. |13.5        |77   |Japan |
|Mazda RX-7 GS               |23.7|3        |70.00       |100.0     |2420. |12.5        |80   |Japan |
|Volkswagen 1131 Deluxe Sedan|26.0|4        |97.00       |46.00     |1835. |20.5        |70   |Europe|
+----------------------------+----+---------+------------+----------+------+------------+-----+------+
only showing top 5 rows



In [None]:
# To change the sorting order, you can use the ascending parameter:

df.orderBy('Cylinders', ascending=False).show(4,truncate=False)

+-------------------------+----+---------+------------+----------+------+------------+-----+------+
|Car                      |MPG |Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|
+-------------------------+----+---------+------------+----------+------+------------+-----+------+
|Chevrolet Chevelle Malibu|18.0|8        |307.0       |130.0     |3504. |12.0        |70   |US    |
|Buick Skylark 320        |15.0|8        |350.0       |165.0     |3693. |11.5        |70   |US    |
|Plymouth Satellite       |18.0|8        |318.0       |150.0     |3436. |11.0        |70   |US    |
|AMC Rebel SST            |16.0|8        |304.0       |150.0     |3433. |12.0        |70   |US    |
+-------------------------+----+---------+------------+----------+------+------------+-----+------+
only showing top 4 rows



## Numeric functions

See [here](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/functions.html#aggregate-functions) for aggregate functions and see [here](https://spark.apache.org/docs/latest/api/python/reference/pyspark.sql/functions.html#math-functions) for maths functions

In [None]:
from pyspark.sql.functions import min,sum,max, stddev, kurtosis, skewness, median,isnan

In [None]:
sample = pd.DataFrame(np.random.normal(loc = 3.0,
                                       scale = 1.5,
                                       size = (10,3)
                                       ),
                                      columns = ['a','b','c']
                     )

sample.head()

Unnamed: 0,a,b,c
0,4.184224,2.924884,3.130759
1,2.91376,6.140127,2.54709
2,4.611158,3.182013,2.30193
3,2.766,0.156453,3.077561
4,0.56942,3.065259,5.831507


In [None]:
sample.iloc[0,0] = np.nan
sample.iloc[1,2] = np.nan
sample.head()

Unnamed: 0,a,b,c
0,,2.924884,3.130759
1,2.91376,6.140127,
2,4.611158,3.182013,2.30193
3,2.766,0.156453,3.077561
4,0.56942,3.065259,5.831507


In [None]:
sample = spark.createDataFrame(sample)
sample.show()

+------------------+-------------------+------------------+
|                 a|                  b|                 c|
+------------------+-------------------+------------------+
|               NaN| 2.9248843834881906|  3.13075851813386|
| 2.913760304534459|  6.140127024174712|               NaN|
|4.6111578725355375| 3.1820130551569736|2.3019296977915666|
|2.7659995094893297|0.15645272344707006| 3.077561218569314|
|0.5694203573459866| 3.0652594954113126| 5.831507038789585|
| 2.869106852077457| 2.6348208585075885|1.5351812599720445|
|1.7001755330051531| 3.9801901032250653|1.9656220963196793|
|1.6938591891505042| 1.0878575411566203| 1.944088864970868|
| 2.175122462364656| 3.1508962208759934|  4.59441294183315|
| 2.289952682482618|  4.023203028196816| 4.055936262788871|
+------------------+-------------------+------------------+



In [None]:
# Does a NaN exist?
sample.select(isnan(sample.a).alias('n')).show(3)

# NaN will have to be dropped to calculate stat functions:
sample.dropna().select(skewness(sample.a), stddev(sample['b']))

+-----+
|    n|
+-----+
| true|
|false|
|false|
+-----+
only showing top 3 rows



skewness(a),stddev(b)
0.5711326713004375,1.363763238707429


<a id='union-dataframes'></a>
### Union Dataframes

You will see three main methods for performing union of dataframes. It is important to know the difference between them and which one is preferred:

*   `union()` – It is used to merge two DataFrames of the same structure/schema. If schemas are not the same, it returns an error
*   `unionAll()` – This function is deprecated since Spark 2.0.0, and replaced with union()
*   `unionByName()` - This function is used to merge two dataframes based on column name.

> Since `unionAll()` is deprecated, **`union()` is the preferred method for merging dataframes.**
<br>
> The difference between `unionByName()` and `union()` is that `unionByName()` resolves columns by name, not by position.

In other SQLs, Union eliminates the duplicates but UnionAll merges two datasets, thereby including duplicate records. But, in PySpark, both behave the same and includes duplicate records. The recommendation is to use `distinct()` or `dropDuplicates()` to remove duplicate records.

In [None]:
# CASE 1: Union When columns are in order
df = spark.read.csv('cars.csv', header=True, sep=";", inferSchema=True)
europe_cars = df.filter((col('Origin')=='Europe') & (col('Cylinders')==5))
japan_cars = df.filter((col('Origin')=='Japan') & (col('Cylinders')==3))
print("EUROPE CARS: "+str(europe_cars.count()))
print("JAPAN CARS: "+str(japan_cars.count()))
print("AFTER UNION: "+str(europe_cars.union(japan_cars).count()))

EUROPE CARS: 3
JAPAN CARS: 4
AFTER UNION: 7


**Result:**

> As you can see here, there were 3 cars from Europe with 5 Cylinders, and 4 cars from Japan with 3 Cylinders. After union, there are 7 cars in total.



In [None]:
# CASE 1: Union When columns are not in order
# Creating two dataframes with jumbled columns
df1 = spark.createDataFrame([[1, 2, 3]], ["col0", "col1", "col2"])
df2 = spark.createDataFrame([[4, 5, 6]], ["col1", "col2", "col0"])
df1.unionByName(df2).show()

+----+----+----+
|col0|col1|col2|
+----+----+----+
|   1|   2|   3|
|   6|   4|   5|
+----+----+----+



**Result:**

> As you can see here, the two dataframes have been successfully merged based on their column names.



In [None]:
from pyspark.sql.functions import min, max
df.select(min(col('Weight')), max(col('Weight'))).show()

<a id='common-data-manipulation-functions'></a>
## Common Data Manipulation Functions

In [None]:
# Functions available in PySpark
from pyspark.sql import functions
# Similar to python, we can use the dir function to view the avaiable functions
print(dir(functions))



<a id='string-functions'></a>
### String Functions

In [None]:
# Loading the data
from pyspark.sql.functions import col
df = spark.read.csv('cars.csv', header=True, sep=";", inferSchema=True)

**Display the Car column in exisitng, lower and upper characters, and the first 4 characters of the column**

In [None]:
from pyspark.sql.functions import col, lower, upper, substring
# Prints out the details of a function
# help(substring)
# alias is used to rename the column name in the output
df.select(col('Car'),lower(col('Car')),upper(col('Car')),substring(col('Car'),1,4).alias("concatenated value")).show(5, False)

+-------------------------+-------------------------+-------------------------+------------------+
|Car                      |lower(Car)               |upper(Car)               |concatenated value|
+-------------------------+-------------------------+-------------------------+------------------+
|Chevrolet Chevelle Malibu|chevrolet chevelle malibu|CHEVROLET CHEVELLE MALIBU|Chev              |
|Buick Skylark 320        |buick skylark 320        |BUICK SKYLARK 320        |Buic              |
|Plymouth Satellite       |plymouth satellite       |PLYMOUTH SATELLITE       |Plym              |
|AMC Rebel SST            |amc rebel sst            |AMC REBEL SST            |AMC               |
|Ford Torino              |ford torino              |FORD TORINO              |Ford              |
+-------------------------+-------------------------+-------------------------+------------------+
only showing top 5 rows



**Concatenate the Car column and Model column and add a space between them.**

In [None]:
from pyspark.sql.functions import concat
df.select(col("Car"),col("model"),concat(col("Car"), lit(" "), col("model"))).show(5, False)

+-------------------------+-----+----------------------------+
|Car                      |model|concat(Car,  , model)       |
+-------------------------+-----+----------------------------+
|Chevrolet Chevelle Malibu|70   |Chevrolet Chevelle Malibu 70|
|Buick Skylark 320        |70   |Buick Skylark 320 70        |
|Plymouth Satellite       |70   |Plymouth Satellite 70       |
|AMC Rebel SST            |70   |AMC Rebel SST 70            |
|Ford Torino              |70   |Ford Torino 70              |
+-------------------------+-----+----------------------------+
only showing top 5 rows



<a id='joins-in-pyspark'></a>
## Joins in PySpark

In [None]:
# Create two dataframes
cars_df = spark.createDataFrame([[1, 'Car A'],[2, 'Car B'],[3, 'Car C']], ["id", "car_name"])
car_price_df = spark.createDataFrame([[1, 1000],[2, 2000],[3, 3000]], ["id", "car_price"])
cars_df.show()
car_price_df.show()

+---+--------+
| id|car_name|
+---+--------+
|  1|   Car A|
|  2|   Car B|
|  3|   Car C|
+---+--------+

+---+---------+
| id|car_price|
+---+---------+
|  1|     1000|
|  2|     2000|
|  3|     3000|
+---+---------+



In [None]:
# Executing an inner join so we can see the id, name and price of each car in one row
cars_df.join(car_price_df, cars_df.id == car_price_df.id, 'inner').select(cars_df['id'],cars_df['car_name'],car_price_df['car_price']).show(truncate=False)

+---+--------+---------+
|id |car_name|car_price|
+---+--------+---------+
|1  |Car A   |1000     |
|2  |Car B   |2000     |
|3  |Car C   |3000     |
+---+--------+---------+



As you can see, we have done an inner join between two dataframes. The following joins are supported by PySpark:
1. inner (default)
2. cross
3. outer
4. full
5. full_outer
6. left
7. left_outer
8. right
9. right_outer
10. left_semi
11. left_anti

<a id='spark-sql'></a>
## Spark SQL

SQL has been around since the 1970s, and so one can imagine the number of people who made it their bread and butter. As big data came into popularity, the number of professionals with the technical knowledge to deal with it was in shortage. This led to the creation of Spark SQL. To quote the docs:<br>
>Spark SQL is a Spark module for structured data processing. Unlike the basic Spark RDD API, the interfaces provided by Spark SQL provide Spark with more information about the structure of both the data and the computation being performed. Internally, Spark SQL uses this extra information to perform extra optimizations.

Basically, what you need to know is that Spark SQL is used to execute SQL queries on big data. Spark SQL can also be used to read data from Hive tables and views. Let me explain Spark SQL with an example.


In [None]:
# Load data
df = spark.read.csv('cars.csv', header=True, sep=";")
# Register Temporary Table
df.createOrReplaceTempView("temp")
# Select all data from temp table
spark.sql("select * from temp limit 5").show()
# Select count of data in table
spark.sql("select count(*) as total_count from temp").show()

+--------------------+----+---------+------------+----------+------+------------+-----+------+
|                 Car| MPG|Cylinders|Displacement|Horsepower|Weight|Acceleration|Model|Origin|
+--------------------+----+---------+------------+----------+------+------------+-----+------+
|Chevrolet Chevell...|18.0|        8|       307.0|     130.0| 3504.|        12.0|   70|    US|
|   Buick Skylark 320|15.0|        8|       350.0|     165.0| 3693.|        11.5|   70|    US|
|  Plymouth Satellite|18.0|        8|       318.0|     150.0| 3436.|        11.0|   70|    US|
|       AMC Rebel SST|16.0|        8|       304.0|     150.0| 3433.|        12.0|   70|    US|
|         Ford Torino|17.0|        8|       302.0|     140.0| 3449.|        10.5|   70|    US|
+--------------------+----+---------+------------+----------+------+------------+-----+------+

+-----------+
|total_count|
+-----------+
|        406|
+-----------+



As you can see, we registered the dataframe as temporary table and then ran basic SQL queries on it. How amazing is that?!<br>
If you are a person who is more comfortable with SQL, then this feature is truly a blessing for you! But this raises a question:
> *Should I just keep using Spark SQL all the time?*

And the answer is, _**it depends**_.<br>
So basically, the different functions acts in differnet ways, and depending upon the type of action you are trying to do, the speed at which it completes execution also differs. But as time progress, this feature is getting better and better, so hopefully the difference should be a small margin. There are plenty of analysis done on this, but nothing has a definite answer yet. You can read this [comparative study done by horton works](https://community.cloudera.com/t5/Community-Articles/Spark-RDDs-vs-DataFrames-vs-SparkSQL/ta-p/246547) or the answer to this [stackoverflow question](https://stackoverflow.com/questions/45430816/writing-sql-vs-using-dataframe-apis-in-spark-sql) if you are still curious about it.

> With map, you define a function and then apply it record by record. Flatmap returns a new RDD by first applying a function to all of the elements in RDDs and then flattening the result. Filter, returns a new RDD. Meaning only the elements that satisfy a condition. With reduce, we are taking neighboring elements and producing a single combined result.
For example, let's say you have a set of numbers. You can reduce this to its sum by providing a function that takes as input two values and reduces them to one.

Some of the reasons you would use a dataframe over RDD are:
1.   It's ability to represnt data as rows and columns. But this also means it can only hold structred and semi-structured data.
2.   It allows processing data in different formats (AVRO, CSV, JSON, and storage system HDFS, HIVE tables, MySQL).
3. It's superior job Optimization capability.
4. DataFrame API is very easy to use.





<a id='common-questions'></a>
# Common Questions
No code cells exist here

<a id='submitting-a-spark-job'></a>
## Submitting a Spark Job

The python syntax for running jobs is: `python <file_name>.py <arg1> <arg2> ...`
<br>But when you submit a spark job you have to use spark-submit to run the application.

Here is a simple example of a spark-submit command:
`spark-submit filename.py --named_argument 'arguemnt value'`<br>
Here, named_argument is an argument that you are reading from inside your script.

There are other options you can pass in the command, like:<br>
`--py-files` which helps you pass a python file to read in your file,<br>
`--files` which helps pass other files like txt or config,<br>
`--deploy-mode` which tells wether to deploy your worker node on cluster or locally <br>
`--conf` which helps pass different configurations, like memoryOverhead, dynamicAllocation etc.

There is an [entire page](https://spark.apache.org/docs/latest/submitting-applications.html) in spark documentation dedicated to this. I highly recommend you go through it once.

<a id='fine-tuning-a-pyspark-job'></a>
## Fine Tuning a Spark Job

Before we begin, please note that this entire section is written purely based on experience. It might differ with use cases, but it will help you get a better understanding of what you should be looking for, or act as a guidance to achieve your aim.

>Spark Performance Tuning refers to the process of adjusting settings to record for memory, cores, and instances used by the system. This process guarantees that the Spark has a flawless performance and also prevents bottlenecking of resources in Spark.

Considering you are using Amazon EMR to execute your spark jobs, there are three aspects you need to take care of:
1. EMR Sizing
2. Spark Configurations
3. Job Tuning



<a id='emr-sizing'></a>
### EMR Sizing

Sizing your EMR is extremely important, as this affects the efficency of your spark jobs. Apart from the cost factor, the maximum number of nodes and memory your job can use will be decided by this. If you spin up a EMR with high specifications, that obviously means you are paying more for it, so we should ideally utilize it to the max. These are the guidelines that I follow to make sure the EMR is rightly sized:

1. Size of the input data (include all the input data) on the disk.
2. Whether the jobs have transformations or just a straight pass through.<br> Assess the joins and the complex joins involved.
3. Size of the output data on the disk.

Look at the above criteria against the memory you need to process, and the disk space you would need. Start with a small configuration, and keep adding nodes to arrive at an optimal configuration. In case you are wondering about the *Execution time vs EMR configuration* factor, please understand that it is okay for a job to run longer, rather than adding more resources to the cluster. For example, it is okay to run a job for 40 mins job on a 5 node cluster, rather than running a job in 10 mins on a 15 node cluster.


Another thing you need to know about EMRs, are the different kinds of EC2 instance types provided by Amazon. I will briefly talk about them, but I strongly recommend you to read more about it from the [official documentation](https://aws.amazon.com/ec2/instance-types/). There are 5 types of instance classes. Based on the job you want to run, you can decide which one to use:

>Instance Class | Description
>--- | ---
>General purpose | Balance of compute, memory and networking resources
>Compute optimized | Ideal for compute bound applications that benefit from high performance processors
>Memory optimized | Designed to deliver fast performance for workloads that process large data sets in memory
>Storage optimized | For workloads that require high, sequential read and write access to very large data sets on local storage
>GPU instances | Use hardware accelerators, or co-processors, to perform high demanding functions, more efficiently than is possible in software running on CPUs

The configuration (memory, storage, cpu, network performance) will differ based on the instance class you choose.<br>
To help make life easier, here is what I do when I get into a predicament about which one to go with: <br>
 1. Visit [ec2instances](https://www.ec2instances.info/)
 2. Choose the EC2 instances in question
 3. Click on compare selected

This will easily help you undesrstand what you are getting into, and thereby help you make the best choice! The site was built by [Garret Heaton](https://github.com/powdahound)(founder of Swoot), and has helped me countless number of times to make an informed decision.

<a id='spark-configurations'></a>
### Spark Configurations

There are a ton of [configurations](https://spark.apache.org/docs/latest/configuration.html) that you can tweak when it comes to Spark. Here, I will be noting down some of the configurations which I use, which have worked well for me. Alright! let's get into it!

#### Job Scheduling

When you submit your job in a cluster, it will be given to Spark Schedulers, which is responsible for materializing a logical plan for your job. There are two types of [job scheduling](https://spark.apache.org/docs/latest/job-scheduling.html):
1. FIFO<br>
By default, Spark’s scheduler runs jobs in FIFO fashion. Each job is divided into stages (e.g. map and reduce phases), and the first job gets priority on all available resources while its stages have tasks to launch, then the second job gets priority, etc. If the jobs at the head of the queue don’t need to use the whole cluster, later jobs can start to run right away, but if the jobs at the head of the queue are large, then later jobs may be delayed significantly.
2. FAIR<br>
The fair scheduler supports grouping jobs into pools and setting different scheduling options (e.g. weight) for each pool. This can be useful to create a high-priority pool for more important jobs, for example, or to group the jobs of each user together and give users equal shares regardless of how many concurrent jobs they have instead of giving jobs equal shares. This approach is modeled after the Hadoop Fair Scheduler.

> I personally prefer using the FAIR mode, and this can be set by adding `.config("spark.scheduler.mode", "FAIR")` when you create your SparkSession.


#### Serializer

We have two types of [serializers](https://spark.apache.org/docs/latest/tuning.html#data-serialization) available:
1. Java serialization
2. Kryo serialization

Kryo is significantly faster and more compact than Java serialization (often as much as 10x), but does not support all Serializable types and requires you to register the classes you’ll use in the program in advance for best performance.

Java serialization is used by default because if you have custom class that extends Serializable it can be easily used. You can also control the performance of your serialization more closely by extending java.io.Externalizable

> The general recommendation is to use Kyro as the serializer whenver possible, as it leads to much smaller sizes than Java serialization. It can be added by using `.config("spark.serializer", "org.apache.spark.serializer.KryoSerializer")` when you create your SparkSession.


#### Shuffle Behaviour

It is generally a good idea to compress the output file after the map phase. The `spark.shuffle.compress` property decides whether to do the compression or not. The compression used is `spark.io.compression.codec`.

> The property can be added by using `.config("spark.shuffle.compress", "true")` when you create your SparkSession.

#### Compression and Serialization

There are 4 defaiult codecs spark provides to compress internal data such as RDD partitions, event log, broadcast variables and shuffle outputs. They are:

1. lz4
2. lzf
3. snappy
4. zstd

> The decision on which to use rests upon the use case. I generally use the `snappy` compression. Google created Snappy because they needed something that offered very fast compression at the expense of final size. Snappy is fast, stable and free, but it increases the size more than the other codecs. At the same time, since compute costs will be less, it seems like balanced trade off. The property can be added by using `.config("spark.io.compression.codec", "snappy")` when you create your SparkSession.

This [session](https://databricks.com/session/best-practice-of-compression-decompression-codes-in-apache-spark) explains the best practice of compression/decompression codes in Apache Spark. I recommend you to take a look at it before taking a decision.

#### Scheduling

The property `spark.speculation` performs speculative execution of tasks. This means if one or more tasks are running slowly in a stage, they will be re-launched. Speculative execution will not stop the slow running task but it launches the new task in parallel.

> I usually disable this option by adding `.config("spark.speculation", "false") ` when I create the SparkSession.

#### Application Properties

There are mainly two application properties that you should know about:

1. spark.driver.memoryOverhead - The amount of off-heap memory to be allocated per driver in cluster mode, in MiB unless otherwise specified. This is memory that accounts for things like VM overheads, interned strings, other native overheads, etc. This tends to grow with the container size (typically 6-10%). This option is currently supported on YARN and Kubernetes.

2. spark.executor.memoryOverhead - The amount of off-heap memory to be allocated per executor, in MiB unless otherwise specified. This is memory that accounts for things like VM overheads, interned strings, other native overheads, etc. This tends to grow with the executor size (typically 6-10%). This option is currently supported on YARN and Kubernetes.

> If you ever face an issue like `Container killed by YARN for exceeding memory limits`, know that it is because you have not specified enough memory Overhead for your job to successfully execute. The default value for Overhead is 10% of avaialbe memory (driver/executor sepearte), with minimum of 384.



#### Dynamic Allocation

Lastly, I want to talk about Dynamic Allocation. This is a feature I constantly use while executing my jobs. This property is by defualt set to False. As the name suggests, it sets whether to use dynamic resource allocation, which scales the number of executors registered with this application up and down based on the workload. Truly a wonderful feature, and the greatest benefit of using it is that it will help make the best use of all the resources you have! The disadvantage of this feature is that it does not shine well when you have to execute tasks in parallel. Since most of the resources will be used by the first task, the second one will have to wait till some resource gets released. At the same time, if both get submitted at the exact same time, the resources will be shared between them, although not equally. Also, it is not guaranteed to *always* use the most optimal configurations. But in all my tests, the results have been great!

> If you are planning on using this feature, you can pass the configurations as required through the spark-submit command. The four configurations which you will have to keep in mind are:<br>
```
--conf spark.dynamicAllocation.enabled=true
--conf spark.dynamicAllocation.initialExecutors
--conf spark.dynamicAllocation.minExecutors
--conf spark.dynamicAllocation.maxExecutors
```

You can read more about this feature [here](https://spark.apache.org/docs/latest/configuration.html#dynamic-allocation) and [here](https://stackoverflow.com/questions/40200389/how-to-execute-spark-programs-with-dynamic-resource-allocation).





<a id='job-tuning'></a>
### Job Tuning

Apart from EMR and Spark tuning, there is another way to approach opttimizations, and that is by tuning your job itself to produce results efficently. I will be going over some such techniques which will help you achieve this. The [Spark Programming Guide](https://spark.apache.org/docs/2.1.1/programming-guide.html) talks more about these concepts in detail. If you guys prefer watching a video over reading, I highly recommend [A Deep Dive into Proper Optimization for Spark Jobs](https://youtu.be/daXEp4HmS-E) by Daniel Tomes from Databricks, which I found really useful and informative!

#### Broadcast Joins (Broadcast Hash Join)

For some jobs, the efficenecy can be increased by caching them in memory. Broadcast Hash Join(BHJ) is such a technique which will help you optimize join queries when the size of one side of the data is low.
>BroadCast joins are the fastest but the drawaback is that it will consume more memory on both the executor and driver.

This following steps give a sneak peek into how it works, which will help you understand the use cases where it can be used:<br>
1. Input file(smaller of the two tables) to be broadcasted is read by the executors in parallel into its working memory.
2. All the data from the executors is collected into driver (Hence, the need for higher memory at driver).
3. The driver then broadcasts the combined dataset (full copy) into each executor.
4. The size of the broadcasted dataset could be several (10-20+) times bigger the input in memory due to factors like deserialization.
5. Executors will end up storing the parts it read first, and also the full copy, thereby leading to a high memory requirement.

Some things to keep in mind about BHJ:
1. It is advisable to use broadcast joins on small datasets only (dimesnion table, for example).
2. Spark does not guarantee BHJ is always chosen, since not all cases (e.g. full outer join) support BHJ.
3. You could notice skews in tasks due to uneven partition sizes; especially during aggregations, joins etc. This can be evened out by introducing Salt value (random value).<br>*Suggested formula for salt value:* random(0 – (shuffle partition count – 1))


#### Spark Partitions

A partition in spark is an atomic chunk of data (logical division of data) stored on a node in the cluster. Partitions are the basic units of parallelism in Spark. Having too large a number of partitions or too few is not an ideal solution. The number of partitions in spark should be decided based on the cluster configuration and requirements of the application. Increasing the number of partitions will make each partition have less data or no data at all. Generally, spark partitioning can be broken down in three ways:
1. Input
2. Shuffle
3. Output


##### Input

Spark usually does a good job of figuring the ideal configuration for this one, except in very particular cases. It is advisable to use the spark default unless:
1. Increase parallelism
2. Heavily nested data
3. Generating data (explode)
4. Source is not optimal
5. You are using UDFs

`spark.sql.files.maxpartitionBytes`: This property indicates the maximum number of bytes to pack into a single partition when reading files (Default 128 MB) . Use this to increase the parallelism in reading input data. For example, if you have more cores, then you can increase the number of parallel tasks which will ensure usage of the all the cores of the cluster, and increase the speed of the task.

##### Shuffle

One of the major reason why most jobs lags in performance is, for the majority of the time, because they get the shuffle partitions count wrong. By default, the value is set to 200. In almost all situations, this is not ideal. If you are dealing with shuffle satge of less than 20 GB, 200 is fine, but otherwise this needs to be changed. For most cases, you can use the following equation to find the right value:
>`Partition Count = Stage Input Data / Target Size` where <br>
`Largest Shuffle Stage (Target Size) < 200MB/partition` in most cases.<br>
`spark.sql.shuffle.partitions` property is used to set the ideal partition count value.

If you ever notice that target size at the range of TBs, there is something terribly wrong, and you might want to change it back to 200, or recalculate it. Shuffle partitions can be configured for every action (not transformation) in the spark script.

Let us use an example to explain this scenario: <br>
Assume shuffle stage input = 210 GB. <br>
Partition Count = Stage Input Data / Target Size = 210000 MB/200 MB = 1050. <br>
As you can see, my shuffle partitions should be 1050, not 200.

But, if your cluster has 2000 cores, then set your shuffle partitions to 2000.
>In a large cluster dealing with a large data job, never set your shuffle partitions less than your total core count.



Shuffle stages almost always precede the write stages and having high shuffle partition count creates small files in the output. To address this, use localCheckPoint just before write & do a coalesce call. This localCheckPoint writes the Shuffle Partition to executor local disk and then coalesces into lower partition count and hence improves the overall performance of both shuffle stage and write stage.

##### Output

There are different methods to write the data. You can control the size, composition, number of files in the output and even the number of records in each file while writing the data. While writing the data, you can increase the parallelism, thereby ensuring you use all the resources that you have. But this approach would lead to a larger number of smaller files. Usually, this isn't a problem, but if you want bigger files, you will have to use one of the compaction techniques, preferably in a cluster with lesser configuration. There are multiple ways to change the composition of the output. Keep these two in mind about composition:
1. Coalesce: Use this to reduce the number of partitions.
2. Repartition: Use this very rarely, and never to reduce the number of partitions<br>
    a. Range Paritioner - It partitions the data either based on some sorted order OR set of sorted ranges of keys. <br>
    b. Hash Partioner - It spreads around the data in the partitioning based upon the key value. Hash partitioning can make distributed data skewed.

<a id='best-practices'></a>
### Best Practices

Try to incorporate these to your coding habits for better performance:
1.   Do not use NOT IN use NOT EXISTS.
2.   Remove Counts, Distinct Counts (use approxCountDIstinct).
3.   Drop Duplicates early.
4.   Always prefer SQL functions over PandasUDF.
5.   Use Hive partitions effectively.
6.   Leverage Spark UI effectively.
7.   Avoid Shuffle Spills.
8.   Aim for target cluster utilization of atleast 70%.



In [None]:
############## DONE #############