# RDD basics

**NOTE: This notebook is worth 10% of the grade of project 2.**

#### [Introduction to Spark with Python, by Jose A. Dianes](https://github.com/jadianes/spark-py-notebooks)

This notebook will introduce three basic but essential Spark operations. Two of them are the *transformations* `map` and `filter`. The other is the *action* `collect`. At the same time we will introduce the concept of *persistence* in Spark.    

Fill in the following cells where a TODO is given. Then run each cell by press SHIFT + ENTER. The results will be printed below the cells.

## Getting the data and creating the RDD

In this notebook we will use the reduced dataset (1 percent) provided for the KDD Cup 1999, containing nearly half million network interactions. The file is provided as a *Gzip* file in the local directory.  

In [3]:
import os
from pyspark import SparkContext
data_file = "file://" + os.getcwd() + "/../kddcup.data_1_percent.gz"
sc=SparkContext.getOrCreate()
raw_data = sc.textFile(data_file)

## The `filter` transformation

This transformation can be applied to RDDs in order to keep just elements that satisfy a certain condition. More concretely, a function is evaluated on every element in the original RDD. The new resulting RDD will contain just those elements that make the function return `True`.

For example, imagine we want to count how many `normal.` interactions we have in our dataset. We can filter our `raw_data` RDD as follows.  

In [4]:
# TODO: create a RDD called 'normal_raw_data' by filtering 'raw_data' with only data with 'normal.' in the row.
normal_raw_data = raw_data.filter(lambda x: "normal." in x)

#print(normal_raw_data.count())
print(type(normal_raw_data))

<class 'pyspark.rdd.PipelinedRDD'>


Now we can count how many elements we have in the new RDD.

In [5]:
from time import time
t0 = time()

# TODO: store the count of 'normal_raw_data' to 'normal_count'
normal_count = normal_raw_data.count()

tt = time() - t0
print("There are {} 'normal' interactions".format(normal_count))
print("Count completed in {} seconds".format(round(tt,3)))

There are 9641 'normal' interactions
Count completed in 0.387 seconds


Remember from notebook 1 that we have a total of 49402 in our 1 percent dataset. Here we can see that 9641 contain the `normal.` tag word.  

Notice that we have measured the elapsed time for counting the elements in the RDD. We have done this because we wanted to point out that actual (distributed) computations in Spark take place when we execute *actions* and not *transformations*. In this case `count` is the action we execute on the RDD. We can apply as many transformations as we want on a our RDD and no computation will take place until we call the first action that, in this case takes a few seconds to complete.

## The `map` transformation

By using the `map` transformation in Spark, we can apply a function to every element in our RDD. Python's lambdas are specially expressive for this particular.

In this case we want to read our data file as a CSV formatted one. We can do this by applying a lambda function to each element in the RDD as follows.

In [6]:
from pprint import pprint

# TODO: map each row of 'raw_data' into CSV format, with column separated by comma (,).
csv_data = raw_data.map(lambda x: x.split(","))
t0 = time()

# TODO: process the first 5 rows of `csv_data`
first_five_rows = csv_data.take(5)
tt = time() - t0

print("Parse completed in {} seconds".format(round(tt,3)))
pprint(first_five_rows[0])

Parse completed in 0.098 seconds
['0',
 'udp',
 'private',
 'SF',
 '105',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '2',
 '2',
 '0.00',
 '0.00',
 '0.00',
 '0.00',
 '1.00',
 '0.00',
 '0.00',
 '255',
 '241',
 '0.95',
 '0.01',
 '0.01',
 '0.00',
 '0.00',
 '0.00',
 '0.00',
 '0.00',
 'normal.']


Again, all action happens once we call the first Spark *action* (i.e. *take* in this case). What if we take a lot of elements instead of just the first few?  

In [7]:
t0 = time()
# TODO: now process up to 100000 rows
hundred_thousand_rows = csv_data.take(100000)
tt = time() - t0
print("Parse completed in {} seconds".format(round(tt,3)))

Parse completed in 1.606 seconds


We can see that it takes longer. The `map` function is applied now in a  distributed way to a lot of elements on the RDD, hence the longer execution time.

In [8]:
pprint(hundred_thousand_rows[4])

['0',
 'tcp',
 'smtp',
 'SF',
 '848',
 '334',
 '0',
 '0',
 '0',
 '0',
 '0',
 '1',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '0',
 '1',
 '1',
 '0.00',
 '0.00',
 '0.00',
 '0.00',
 '1.00',
 '0.00',
 '0.00',
 '61',
 '174',
 '0.92',
 '0.05',
 '0.02',
 '0.02',
 '0.00',
 '0.00',
 '0.00',
 '0.00',
 'normal.']


### Using `map` and predefined functions

Of course we can use predefined functions with `map`. Imagine we want to have each element in the RDD as a key-value pair where the key is the tag (e.g. *normal*) and the value is the whole list of elements that represents the row in the CSV formatted file. We could proceed as follows.    

In [9]:
def parse_interaction(line):
    # TODO: Parse the "tag" field from each row of interaction data.
    # The structure of each row is: duration,protocol_type,service,flag,src_bytes,dst_bytes,land,wrong_fragment,
    #   urgent,hot,num_failed_logins,logged_in,num_compromised,root_shell,su_attempted,num_root,num_file_creations,
    #   num_shells,num_access_files,num_outbound_cmds,is_host_login,is_guest_login,count,srv_count,serror_rate,
    #   srv_serror_rate,rerror_rate,srv_rerror_rate,same_srv_rate,diff_srv_rate,srv_diff_host_rate,dst_host_count,
    #   dst_host_srv_count,dst_host_same_srv_rate,dst_host_diff_srv_rate,dst_host_same_src_port_rate,
    #   dst_host_srv_diff_host_rate,dst_host_serror_rate,dst_host_srv_serror_rate,dst_host_rerror_rate,
    #   dst_host_srv_rerror_rate,*tag*
    fields = line.split(",")[:]
    tag = line.split(",")[-1]
    return (tag, fields)

key_csv_data = raw_data.map(parse_interaction)
head_rows = key_csv_data.take(5)
pprint(head_rows[0])

('normal.',
 ['0',
  'udp',
  'private',
  'SF',
  '105',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '0',
  '2',
  '2',
  '0.00',
  '0.00',
  '0.00',
  '0.00',
  '1.00',
  '0.00',
  '0.00',
  '255',
  '241',
  '0.95',
  '0.01',
  '0.01',
  '0.00',
  '0.00',
  '0.00',
  '0.00',
  '0.00',
  'normal.'])


That was easy, wasn't it?

In our notebook about working with key-value pairs we will use this type of RDDs to do data aggregations (e.g. count by key).

## The `collect` action

So far we have used the actions `count` and `take`. Another basic action we need to learn is `collect`. Basically it will get all the elements in the RDD into memory for us to work with them. For this reason it has to be used with care, specially when working with large RDDs.  

An example using our raw data.    

In [10]:
t0 = time()
# TODO: Use collect() to emit the results into a variable called 'all_raw_data' 
all_raw_data = raw_data.collect()
tt = time() - t0
print("Data collected in {} seconds".format(round(tt,3)))

Data collected in 0.679 seconds


That took longer as any other action we used before, of course. Every Spark worker node that has a fragment of the RDD has to be coordinated in order to retrieve its part, and then *reduce* everything together.    

As a last example combining all the previous, we want to collect all the `normal` interactions as key-value pairs.   

In [11]:
import os
from pyspark import SparkContext

# get data from file
data_file = "file://" + os.getcwd() + "/../kddcup.data_1_percent.gz"
sc=SparkContext.getOrCreate()
raw_data = sc.textFile(data_file)

# parse into key-value pairs
key_csv_data = raw_data.map(parse_interaction)

# TODO: create a new RDD called 'normal_key_interactions' by filtering the rows with the tag == "normal."
normal_key_interactions = key_csv_data.filter(lambda x: x[0]=="normal.")

# collect all
t0 = time()
# TODO: Use collect() to emit the results of 'normal_key_interactions' into a variable called 'all_normal'
all_normal = normal_key_interactions.collect()
tt = time() - t0
normal_count = len(all_normal)
print("Data collected in {} seconds".format(round(tt,3)))
print("There are {} 'normal' interactions".format(normal_count))

Data collected in 1.125 seconds
There are 9641 'normal' interactions


This count matches with the previous count for `normal` interactions. The new procedure is more time consuming. This is because we retrieve all the data with `collect` and then use Python's `len` on the resulting list. Before we were just counting the total number of elements in the RDD by using `count`.  