The TIG stack combines three tools: Telegraf collects metrics from the system and services, InfluxDB stores them as time series, and Grafana turns them into dashboards. In this tutorial you will install all three on a single Ubuntu 24.04 server from their official repositories, send CPU, memory, disk and network metrics from Telegraf to an InfluxDB 2 bucket using scoped API tokens, and build a Grafana panel that queries the data with Flux.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS with at least 2 GB of RAM and 20 GB of free disk, for example a CubePath VPS.
  • A non-root user with sudo privileges.
  • UFW enabled with SSH allowed (sudo ufw allow OpenSSH and sudo ufw enable).

All three components run on the same server in this guide. InfluxDB listens on port 8086 and Grafana on port 3000; only Grafana will be reachable from outside.

Step 1 - Adding the InfluxData repository

Telegraf and InfluxDB are both published in the InfluxData APT repository. Download its signing key:

cd /tmp
curl -fsSL -O https://repos.influxdata.com/influxdata-archive.key

Before trusting the key, check its fingerprint:

gpg --show-keys --with-fingerprint influxdata-archive.key

The output must include the fingerprint published in InfluxData's installation docs, 24C9 75CB A61A 024E E1B6 3178 7C3D 5715 9FC2 F927. If it matches, convert the key into a keyring and add the repository:

sudo install -m 0755 -d /etc/apt/keyrings
gpg --dearmor < influxdata-archive.key | sudo tee /etc/apt/keyrings/influxdata-archive.gpg > /dev/null
echo 'deb [signed-by=/etc/apt/keyrings/influxdata-archive.gpg] https://repos.influxdata.com/debian stable main' | sudo tee /etc/apt/sources.list.d/influxdata.list
sudo apt update

apt update should list https://repos.influxdata.com/debian stable InRelease without errors.

Step 2 - Installing and setting up InfluxDB 2

Install the InfluxDB 2 server and its command-line client:

sudo apt install influxdb2 influxdb2-cli
sudo systemctl enable --now influxdb

Check that the API is healthy:

curl -s http://localhost:8086/health
{"name":"influxdb", "message":"ready for queries and writes", "status":"pass", "checks":[], "version": "v2.7.12", "commit": "..."}

A fresh InfluxDB needs an initial user, an organization and a first bucket. Run the setup once, replacing your_strong_password with a password of at least 8 characters:

influx setup \
  --username admin \
  --password 'your_strong_password' \
  --org cubepath \
  --bucket telegraf \
  --retention 30d \
  --force
User	Organization	Bucket
admin	cubepath	telegraf

This creates the cubepath organization and a telegraf bucket that keeps data for 30 days. It also saves an operator token (full access) in ~/.influxdbv2/configs for your user, so the following influx commands authenticate automatically.

Step 3 - Creating scoped API tokens

Telegraf only needs to write to the telegraf bucket and Grafana only needs to read from it. Look up the bucket ID:

influx bucket list --name telegraf
ID			Name		Retention	Shard group duration	Organization ID		Schema Type
a1b2c3d4e5f60718	telegraf	720h0m0s	24h0m0s			0f1e2d3c4b5a6978	implicit

Create a write-only token for Telegraf, replacing your_bucket_id with the ID above:

influx auth create --org cubepath --description "telegraf write" --write-bucket your_bucket_id

Then create a read-only token for Grafana:

influx auth create --org cubepath --description "grafana read" --read-bucket your_bucket_id

Each command prints a table with a Token column. Copy both tokens somewhere safe; you will use them in the next steps.

Step 4 - Installing and configuring Telegraf

Telegraf comes from the same repository:

sudo apt install telegraf

The package ships a very long example configuration that includes the legacy InfluxDB 1.x output. Move it aside and write a short configuration with only what you need:

sudo mv /etc/telegraf/telegraf.conf /etc/telegraf/telegraf.conf.orig
sudo nano /etc/telegraf/telegraf.conf
[agent]
  interval = "10s"
  round_interval = true
  flush_interval = "10s"
  omit_hostname = false

[[outputs.influxdb_v2]]
  urls = ["http://127.0.0.1:8086"]
  token = "${INFLUX_TOKEN}"
  organization = "cubepath"
  bucket = "telegraf"

[[inputs.cpu]]
  percpu = true
  totalcpu = true
  report_active = true

[[inputs.mem]]

[[inputs.swap]]

[[inputs.system]]

[[inputs.processes]]

[[inputs.disk]]
  ignore_fs = ["tmpfs", "devtmpfs", "devfs", "overlay", "squashfs"]

[[inputs.diskio]]

[[inputs.net]]

Each [[inputs.*]] block enables one plugin: CPU usage (with report_active adding a usage_active field), memory and swap, load average and uptime, process counts, filesystem usage and disk and network I/O. The token is not written in the file; Telegraf expands ${INFLUX_TOKEN} from its environment.

The Telegraf systemd unit reads environment variables from /etc/default/telegraf. Store the write token there and make the file readable only by root:

echo 'INFLUX_TOKEN=your_telegraf_write_token' | sudo tee /etc/default/telegraf > /dev/null
sudo chmod 600 /etc/default/telegraf

Before starting the service, run the inputs once in test mode. This prints the collected metrics in line protocol without sending them anywhere:

telegraf --config /etc/telegraf/telegraf.conf --test | head -n 3
> cpu,cpu=cpu0,host=tig-01 usage_active=2.4,usage_idle=97.6,usage_system=1.2,usage_user=1.1 1790245200000000000
> cpu,cpu=cpu-total,host=tig-01 usage_active=2.1,usage_idle=97.9,usage_system=1.0,usage_user=1.0 1790245200000000000
> disk,device=vda1,fstype=ext4,host=tig-01,mode=rw,path=/ free=17122394112i,total=20943937536i,used=3804766208i,used_percent=18.1 1790245200000000000

Start Telegraf and enable it at boot:

sudo systemctl enable --now telegraf
sudo systemctl restart telegraf
sudo systemctl status telegraf --no-pager

The restart makes sure the service reads the new configuration if the package had already started it. The status should be active (running), and sudo journalctl -u telegraf -n 20 should show no 401 Unauthorized or connection errors.

Step 5 - Verifying the data in InfluxDB

Wait about 30 seconds, then query the bucket with Flux to confirm that CPU points are arriving:

influx query 'from(bucket: "telegraf")
  |> range(start: -5m)
  |> filter(fn: (r) => r._measurement == "cpu" and r._field == "usage_active" and r.cpu == "cpu-total")
  |> last()'
Result: _result
Table: keys: [_start, _stop, _field, _measurement, cpu, host]
                   _start:time                      _stop:time           _field:string     _measurement:string             cpu:string            host:string                      _time:time                  _value:float
------------------------------  ------------------------------  ----------------------  ----------------------  ---------------------  ---------------------  ------------------------------  ----------------------------
2026-09-24T10:40:12.000000000Z  2026-09-24T10:45:12.000000000Z            usage_active                     cpu              cpu-total                 tig-01  2026-09-24T10:45:10.000000000Z            2.08

A result with a recent _time means the Telegraf to InfluxDB half of the stack works.

Step 6 - Installing Grafana

Grafana is installed from Grafana Labs' APT repository. Add its key and the repository:

sudo wget -q -O /etc/apt/keyrings/grafana.asc https://apt.grafana.com/gpg.key
echo 'deb [signed-by=/etc/apt/keyrings/grafana.asc] https://apt.grafana.com stable main' | sudo tee /etc/apt/sources.list.d/grafana.list
sudo apt update
sudo apt install grafana

Enable and start the service, then allow its port through the firewall:

sudo systemctl enable --now grafana-server
sudo ufw allow 3000/tcp

Port 8086 stays closed in UFW, so InfluxDB is only reachable from the server itself. Confirm Grafana is listening:

sudo ss -tlnp | grep 3000
LISTEN 0      4096               *:3000             *:*    users:(("grafana",pid=5123,fd=10))

Open http://your_server_ip:3000 in your browser, log in with admin / admin and set a new password when prompted.

Step 7 - Adding InfluxDB as a Grafana data source

You could add the data source in the web UI, but a provisioning file keeps it in version-controllable configuration and survives reinstalls. Create it:

sudo nano /etc/grafana/provisioning/datasources/influxdb.yaml
apiVersion: 1

datasources:
  - name: InfluxDB
    type: influxdb
    access: proxy
    url: http://127.0.0.1:8086
    isDefault: true
    jsonData:
      version: Flux
      organization: cubepath
      defaultBucket: telegraf
    secureJsonData:
      token: your_grafana_read_token

The file contains a token, so make it readable only by root and the grafana group, then restart Grafana:

sudo chown root:grafana /etc/grafana/provisioning/datasources/influxdb.yaml
sudo chmod 640 /etc/grafana/provisioning/datasources/influxdb.yaml
sudo systemctl restart grafana-server

In Grafana, go to Connections > Data sources > InfluxDB and click Test at the bottom of the page. You should see a green message similar to datasource is working. 1 buckets found.

Step 8 - Building a dashboard panel

Create a dashboard with Dashboards > New > New dashboard > Add visualization and pick the InfluxDB data source. Switch the query editor to code and paste this Flux query, which plots total CPU usage per host:

from(bucket: "telegraf")
  |> range(start: v.timeRangeStart, stop: v.timeRangeStop)
  |> filter(fn: (r) => r._measurement == "cpu" and r._field == "usage_active" and r.cpu == "cpu-total")
  |> aggregateWindow(every: v.windowPeriod, fn: mean, createEmpty: false)

v.timeRangeStart, v.timeRangeStop and v.windowPeriod are filled in by Grafana from the dashboard's time picker, so the panel resolution adapts when you zoom. Set the unit to Percent (0-100) under Standard options, give the panel a title and save the dashboard.

Add more panels the same way by changing the measurement and field, for example:

Panel_measurement_field
Memory used %memused_percent
Root disk used %disk (add r.path == "/")used_percent
Load averagesystemload1
Network receivednetbytes_recv (add derivative(unit: 1s, nonNegative: true))

Troubleshooting

  • Telegraf logs 401 Unauthorized: the token in /etc/default/telegraf is wrong or lacks write permission on the bucket. Create a new one as in Step 3 and restart Telegraf.
  • Telegraf logs bucket "telegraf" not found: the organization or bucket in telegraf.conf does not match what you created with influx setup.
  • Grafana test fails with unauthorized: check the read token in the provisioning file and restart grafana-server; provisioning files are read only at startup.
  • Panels show "No data": confirm the query works with influx query on the server, and check that the dashboard time range covers the period since Telegraf started.

Conclusion

You now have a working TIG stack on Ubuntu 24.04: Telegraf collects system metrics every 10 seconds, InfluxDB 2 stores them for 30 days in a dedicated bucket, and Grafana reads them with a read-only token to draw your dashboards. Next, you can install Telegraf on other servers and point them at this InfluxDB (opening port 8086 only to their IPs), add input plugins for Nginx, MySQL or Docker, or put Grafana behind an Nginx reverse proxy with HTTPS.