## Working with Key/value pairs
Spark provides specific functions to deal with RDDs in which each element is a key/value pair. Key/value RDDs expose new operations (e.g. aggregating and grouping together data with the same key and grouping together two different RDDs.) Such RDDs are also called pair RDDs. **In python, each element of a pair RDD is a pair tuple.**

### Creating Pair RDDS

Either load data that directly returns pair RDDs

In [8]:
pair_rdd = sc.parallelize([(1,2), (3,4)])
print pair_rdd.collect()

[(1, 2), (3, 4)]


or apply map() to a function that returns a key/value pair on each element of a regular RDD.

In [5]:
regular_rdd = sc.parallelize([1, 2, 3, 4, 2, 5, 6])
pair_rdd = regular_rdd.map( lambda x: (x, x*x) )
print pair_rdd.collect()

[(1, 1), (2, 4), (3, 9), (4, 16), (2, 4), (5, 25), (6, 36)]


#### Exercise 1
For this exercise, we will use the reduced dataset (10 percent) provided for the KDD Cup 1999, containing nearly half million **nework interactions**. First, download and read the gzip file:

```python
import urllib
f = urllib.urlretrieve ("http://kdd.ics.uci.edu/databases/kddcup99/kddcup.data_10_percent.gz", "kddcup.data_10_percent.gz")
data_file = "./kddcup.data_10_percent.gz"
raw_data = sc.textFile(data_file)
```

Map each comma separated row of this dataset into a list and create a key/value pair RDD with key as x[41] (Network interaction type) and value as x where x is a list. Print the first row of your newly created pair RDD.

Expected output: 

`(u'normal.', [u'0', u'tcp', u'http', u'SF', u'181', u'5450', u'0', u'0', u'0', u'0', u'0', u'1', u'0', u'0', u'0', u'0', u'0', u'0', u'0', u'0', u'0', u'0', u'8', u'8', u'0.00', u'0.00', u'0.00', u'0.00', u'1.00', u'0.00', u'0.00', u'9', u'9', u'1.00', u'0.00', u'0.11', u'0.00', u'0.00', u'0.00', u'0.00', u'0.00', u'normal.'])`

In [1]:
import urllib
f = urllib.urlretrieve ("http://kdd.ics.uci.edu/databases/kddcup99/kddcup.data_10_percent.gz", "kddcup.data_10_percent.gz")
data_file = "./kddcup.data_10_percent.gz"
raw_data = sc.textFile(data_file)

In [2]:
def listDataProcess(x):
    xList = x.split(',')
    return (xList[41], xList)
map_data = raw_data.map(listDataProcess)
print map_data.first()

(u'normal.', [u'0', u'tcp', u'http', u'SF', u'181', u'5450', u'0', u'0', u'0', u'0', u'0', u'1', u'0', u'0', u'0', u'0', u'0', u'0', u'0', u'0', u'0', u'0', u'8', u'8', u'0.00', u'0.00', u'0.00', u'0.00', u'1.00', u'0.00', u'0.00', u'9', u'9', u'1.00', u'0.00', u'0.11', u'0.00', u'0.00', u'0.00', u'0.00', u'0.00', u'normal.'])


### Some important Key-Value Transformations
#### 1. reduceByKey(func): Apply the reduce function on the values with the same key. 

In [11]:
rdd = sc.parallelize([(1,2), (2,4), (2,6)])
print "Original RDD :", rdd.collect()
print "After transformation : ", rdd.reduceByKey(lambda a,b: a+b).collect()

Original RDD :  [(1, 2), (2, 4), (2, 6)]
After transformation :  [(1, 2), (2, 10)]


Note that although it is similar to the reduce function, it is implemented as a transformation and not as an action because the dataset can have very large number of keys. So, it does not return values to the driver program. Instead, it returns a new RDD. 

#### 2. sortByKey(): 
Sort RDD by keys in ascending order. 

In [5]:
rdd = sc.parallelize([(2,2), (1,4), (3,6)])
print "Original RDD :", rdd.collect()
print "After transformation : ", rdd.sortByKey().collect()
print "After transformation(descending) : ", rdd.sortByKey(ascending=False).collect()

Original RDD : [(2, 2), (1, 4), (3, 6)]
After transformation :  [(1, 4), (2, 2), (3, 6)]
After transformation(descending) :  [(3, 6), (2, 2), (1, 4)]


**Note:** The output of sortByKey() is an RDD. This means that  RDDs do have a meaningful order, which extends between partitions.

#### 3. mapValues(func):
Apply func to each value of RDD without changing the key. 

In [2]:
rdd = sc.parallelize([(1,2), (2,4), (2,6)])
print "Original RDD :", rdd.collect()
print "After transformation : ", rdd.mapValues(lambda x: x*2).collect()

Original RDD : [(1, 2), (2, 4), (2, 6)]
After transformation :  [(1, 4), (2, 8), (2, 12)]


#### 4. groupByKey(): 
Returns a new RDD of `(key,<iterator>)` pairs where the iterator iterates over the values associated with the key.

[Iterators](http://anandology.com/python-practice-book/iterators.html) are python objects that generate a sequence of values. Writing a loop over `n` elements as 
```python
for i in range(n):
    ##do something
```
is inefficient because it first allocates a list of `n` elements and then iterates over it.
Using the iterator `xrange(n)` achieves the same result without materializing the list. Instead, elements are generated on the fly.

To materialize the list of values returned by an iterator we will use the list comprehension command:
```python
[a for a in <iterator>]
```

In [6]:
rdd = sc.parallelize([(1,2), (2,4), (2,6)])
print "Original RDD :", rdd.collect()
print "After transformation : ", rdd.groupByKey().mapValues(lambda x:[a for a in x]).collect()

Original RDD : [(1, 2), (2, 4), (2, 6)]
After transformation :  [(2, [4, 6]), (1, [2])]


#### Exercise 2
Continue with the RDD created in last exercise. Print the top 5 network interaction types(with their total durations) which have the largest total durations. Duration is the first column of x, i.e. x[0].

Expected output: 

`
[(u'normal.', 21075991.0), (u'portsweep.', 1991911.0), (u'warezclient.', 627563.0), (u'buffer_overflow.', 2751.0), (u'multihop.', 1288.0)]
`

In [3]:
groupData= map_data.groupByKey().mapValues(lambda x: sum([float(a[0]) for a in x]))
groupDataCol = groupData.collect()
groupDataCol.sort(key=lambda x:x[1], reverse=True)
print groupDataCol[:5]

[(u'normal.', 21075991.0), (u'portsweep.', 1991911.0), (u'warezclient.', 627563.0), (u'buffer_overflow.', 2751.0), (u'multihop.', 1288.0)]


#### 5. flatMapValues(func): 
`func` is a function that takes as input a single value and returns an itrator that generates a sequence of values.
The application of flatMapValues operates on a key/value RDD. It applies `func` to each value, and gets an list (generated by the iterator) of values. It then combines each of the values with the original key to produce a list of kay-value pairs. These lists are concatanated as in `flatMap`

In [3]:
rdd = sc.parallelize([(1,2), (2,4), (2,6)])
print "Original RDD :", rdd.collect()
# the lambda function generates for each number i, an iterator that produces i,i+1
print "After transformation : ", rdd.flatMapValues(lambda x: xrange(x,x+2)).collect()

Original RDD : [(1, 2), (2, 4), (2, 6)]
After transformation :  [(1, 2), (1, 3), (2, 4), (2, 5), (2, 6), (2, 7)]


#### (Advanced) 6. combineByKey(createCombiner, mergeValue, mergeCombiner): 
Combine values with the same key using a different result type.

This is the most general of the per-key aggregation functions. Most of the other per-key combiners are implemented using it. 

The elements of the original RDD are considered here *values*

Values are converted into *combiners* which we will refer to here as "accumulators". An example of such a mapping is the mapping of the value *word* to the accumulator (*word*,1) that is done in WordCount.

accumulators are then combined with values and the other combiner to generate a result for each key.

For example, we can use it to calculate per-activity average durations as follows. Consider an RDD of key/value pairs where keys correspond to different activities and values correspond to duration.


In [4]:
rdd = sc.parallelize([("Sleep", 7), ("Work",5), ("Play", 3), 
                      ("Sleep", 6), ("Work",4), ("Play", 4),
                      ("Sleep", 8), ("Work",5), ("Play", 5)])

sum_counts = rdd.combineByKey(
    (lambda x: (x, 1)), # createCombiner maps each value into a  combiner (or accumulator)
    (lambda acc, value: (acc[0]+value, acc[1]+1)),
#mergeValue defines how to merge a accumulator with a value (saves on mapping each value to an accumulator first)
    (lambda acc1, acc2: (acc1[0]+acc2[0], acc1[1]+acc2[1])) # combine accumulators
)

print sum_counts.collect()
duration_means_by_activity = sum_counts.mapValues(lambda value:
                                                  value[0]*1.0/value[1]) \
                                            .collect()
print duration_means_by_activity

[('Play', (12, 3)), ('Sleep', (21, 3)), ('Work', (14, 3))]
[('Play', 4.0), ('Sleep', 7.0), ('Work', 4.666666666666667)]


To understand combineByKey(), it’s useful to think of how it handles each element it processes. As combineByKey() traverses through the elements in a partition, each element either has a key it hasn’t seen before or has the same key as a previous element.

If it’s a new key, createCombiner() is called to create the initial value for the accumulator on that key. In the above example, the accumulator is a tuple initialized as (x, 1) where x is a value in original RDD. Note that createCombiner() is called only when a key is seen for the first time in **each partition.**

If it is a key we have seen before while processing that partition, it will instead use the provided function, mergeValue(), with the current value for the accumulator for that key and the new value.

Since each partition is processed independently, we can have multiple accumulators for the same key. When we are merging the results from each partition, if two or more partitions have an accumulator for the same key, we merge the accumulators using the user-supplied mergeCombiners() function. In the above example, we are just adding the 2 accumulators element-wise.

### Transformations on two Pair RDDs

In [13]:
rdd1 = sc.parallelize([(1,2),(2,1),(2,2)])
rdd2 = sc.parallelize([(2,5),(3,1)])
a = rdd1.collect()
b = rdd2.collect()
print a,b

 [(1, 2), (2, 1), (2, 2)] [(2, 5), (3, 1)]


#### 1. subtractByKey: 
Remove from RDD1 all elements whose key is present in RDD2.

In [8]:
print "RDD1:", a
print "RDD2:", b
print "Result:", rdd1.subtractByKey(rdd2).collect()

RDD1: [(1, 2), (2, 1), (2, 2)]
RDD2: [(2, 5), (3, 1)]
Result: [(1, 2)]


#### 2. join: 

Perform an inner join between two RDDs.

**Join** is a fundamental operation in relational databases. The basic operation assumes that two tables have a column in common. The join operation marges rows with the same key.

Suppose we have two `(key,value)` datasets 

**dataset 1**

|  key=name   |   (gender,occupation,age)    |
|--------|------------|
| John   |  (male,cook,21) |
| Jill   |  (female,programmer,19) |
| John   |  (male, kid, 2) |
| Kate   |  (female, wrestler, 54) |

**dataset 2**

|  key=name   |   hair color    |
|--------|----------------------|
| Jill   |  blond |
| Grace  |  brown |
| John   |  black |

When `Join` is called on datasets of type `(K, V)` and `(K, W)`, it  returns a dataset of `(K, (V, W))` pairs with all pairs of elements for each key. Joinin the 2 datasets above yields:

|   key = name | (gender,occupation,age),haircolor |
|--------------|-----------------------------------|
| John         | ((male,cook,21),black)             |
| John         | ((male, kid, 2),black)             |
| Jill         | ((female,programmer,19),blond)     |

There are four variants of `join` which differ in how they treat keys that appear in one dataset but not the other.
* `join` is an *inner* join which means that keys that appear only in one dataset are eliminated.
* `leftOuterJoin` keeps all keys from the left dataset even if they don't appear in the right dataset. The result of leftOuterJoin in our example will contain the keys `John, Jill, Kate`
* `rightOuterJoin` keeps all keys from the right dataset even if they don't appear in the left dataset. The result of leftOuterJoin in our example will contain the keys `Jill, Grace, John`
* `FullOuterJoin` keeps all keys from both datasets. The result of leftOuterJoin in our example will contain the keys `Jill, Grace, John, Kate`

In outer joins, if the element appears only in one dataset, the element in `(K,(V,W))` that does not appear in the dataset is represented bye `None`

In [15]:
print "RDD1:", a
print "RDD2:", b
print "Result:", rdd1.join(rdd2).collect()
print "FullOuterJoin:", rdd1.fullOuterJoin(rdd2).collect()

RDD1: [(1, 2), (2, 1), (2, 2)]
RDD2: [(2, 5), (3, 1)]
Result: [(2, (1, 5)), (2, (2, 5))]
FullOuterJoin: [(1, (2, None)), (2, (1, 5)), (2, (2, 5)), (3, (None, 1))]


#### 3. rightOuterJoin: 
Perform a right join between two RDDs. Every key in the right/second RDD will be present at least once.

In [53]:
print "RDD1:", a
print "RDD2:", b
print "Result:", rdd1.rightOuterJoin(rdd2).collect()

RDD1: [(1, 2), (2, 1), (2, 2)]
RDD2: [(2, 5), (3, 1)]
Result: [(2, (1, 5)), (2, (2, 5)), (3, (None, 1))]


#### 4. leftOuterJoin: Perform a left join between two RDDs. Every key in the left RDD will be present at least once.

In [54]:
print "RDD1:", a
print "RDD2:", b
print "Result:", rdd1.leftOuterJoin(rdd2).collect()

RDD1: [(1, 2), (2, 1), (2, 2)]
RDD2: [(2, 5), (3, 1)]
Result: [(2, (1, 5)), (2, (2, 5)), (1, (2, None))]


### Actions on Pair RDDs

In [45]:
rdd = sc.parallelize([(1,2), (2,4), (2,6)])
a = rdd.collect()

#### 1. countByKey(): Count the number of elements for each key. Returns a dictionary for easy access to keys.

In [46]:
print "RDD: ", a
result = rdd.countByKey()
print "Result:", result

RDD:  [(1, 2), (2, 4), (2, 6)]
Result: defaultdict(<type 'int'>, {1: 1, 2: 2})


#### 2. collectAsMap(): 
Collect the result as a dictionary to provide easy lookup.

In [48]:
print "RDD: ", a
result = rdd.collectAsMap()
print "Result:", result

RDD:  [(1, 2), (2, 4), (2, 6)]
Result: {1: 2, 2: 6}


#### 3. lookup(key): 
Return all values associated with the provided key.

In [49]:
print "RDD: ", a
result = rdd.lookup(2)
print "Result:", result

RDD:  [(1, 2), (2, 4), (2, 6)]
Result: [4, 6]


#### Exercise 3
Continue with the RDD created in exercise 2. Use any of the above transformations/actions to calculate and return the average duration for each of the network interaction types. Return the final dataset as a dictionary. You are encouraged to use combineByKey().

Expected output: 

`
{u'guess_passwd.': 2.717, u'nmap.': 0.0, u'loadmodule.': 36.222, u'rootkit.': 100.8, u'warezclient.': 615.258, u'smurf.': 0.0, u'pod.': 0.0, u'neptune.': 0.0, u'normal.': 216.657, u'spy.': 318.0, u'ftp_write.': 32.375, u'phf.': 4.5, u'portsweep.': 1915.299, u'teardrop.': 0.0, u'buffer_overflow.': 91.7, u'land.': 0.0, u'imap.': 6.0, u'warezmaster.': 15.05, u'perl.': 41.333, u'multihop.': 184.0, u'back.': 0.129, u'ipsweep.': 0.034, u'satan.': 0.04}
`

In [12]:
averageRDD = map_data.combineByKey(
    (lambda x: (float(x[0]), 1)),
    (lambda data, value: (data[0] + float(value[0]), data[1] + 1)),
    (lambda data1, data2: (data1[0] + data2[0], data1[1] + data2[1]))
).mapValues(lambda value: value[0] / value[1])

print averageRDD.collectAsMap()

{u'guess_passwd.': 2.7169811320754715, u'nmap.': 0.0, u'loadmodule.': 36.22222222222222, u'rootkit.': 100.8, u'warezclient.': 615.2578431372549, u'smurf.': 0.0, u'pod.': 0.0, u'neptune.': 0.0, u'normal.': 216.65732231336992, u'spy.': 318.0, u'ftp_write.': 32.375, u'phf.': 4.5, u'portsweep.': 1915.2990384615384, u'teardrop.': 0.0, u'buffer_overflow.': 91.7, u'land.': 0.0, u'imap.': 6.0, u'warezmaster.': 15.05, u'perl.': 41.333333333333336, u'multihop.': 184.0, u'back.': 0.1289151157512483, u'ipsweep.': 0.034482758620689655, u'satan.': 0.040276903713027064}
