The TIG stack combines three tools: Telegraf collects metrics from the system and services, InfluxDB stores them as time series, and Grafana turns them into dashboards. In this tutorial you will install all three on a single Ubuntu 24.04 server from their official repositories, send CPU, memory, disk and network metrics from Telegraf to an InfluxDB 2 bucket using scoped API tokens, and build a Grafana panel that queries the data with Flux.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS with at least 2 GB of RAM and 20 GB of free disk, for example a CubePath VPS.
- A non-root user with
sudoprivileges. - UFW enabled with SSH allowed (
sudo ufw allow OpenSSHandsudo ufw enable).
All three components run on the same server in this guide. InfluxDB listens on port 8086 and Grafana on port 3000; only Grafana will be reachable from outside.
Step 1 - Adding the InfluxData repository
Telegraf and InfluxDB are both published in the InfluxData APT repository. Download its signing key:
cd /tmp
curl -fsSL -O https://repos.influxdata.com/influxdata-archive.key
Before trusting the key, check its fingerprint:
gpg --show-keys --with-fingerprint influxdata-archive.key
The output must include the fingerprint published in InfluxData's installation docs, 24C9 75CB A61A 024E E1B6 3178 7C3D 5715 9FC2 F927. If it matches, convert the key into a keyring and add the repository:
sudo install -m 0755 -d /etc/apt/keyrings
gpg --dearmor < influxdata-archive.key | sudo tee /etc/apt/keyrings/influxdata-archive.gpg > /dev/null
echo 'deb [signed-by=/etc/apt/keyrings/influxdata-archive.gpg] https://repos.influxdata.com/debian stable main' | sudo tee /etc/apt/sources.list.d/influxdata.list
sudo apt update
apt update should list https://repos.influxdata.com/debian stable InRelease without errors.
Step 2 - Installing and setting up InfluxDB 2
Install the InfluxDB 2 server and its command-line client:
sudo apt install influxdb2 influxdb2-cli
sudo systemctl enable --now influxdb
Check that the API is healthy:
curl -s http://localhost:8086/health
{"name":"influxdb", "message":"ready for queries and writes", "status":"pass", "checks":[], "version": "v2.7.12", "commit": "..."}
A fresh InfluxDB needs an initial user, an organization and a first bucket. Run the setup once, replacing your_strong_password with a password of at least 8 characters:
influx setup \
--username admin \
--password 'your_strong_password' \
--org cubepath \
--bucket telegraf \
--retention 30d \
--force
User Organization Bucket
admin cubepath telegraf
This creates the cubepath organization and a telegraf bucket that keeps data for 30 days. It also saves an operator token (full access) in ~/.influxdbv2/configs for your user, so the following influx commands authenticate automatically.
WarningThe operator token can do anything on this InfluxDB instance. Do not use it in Telegraf or Grafana; create scoped tokens instead, as shown next.
Step 3 - Creating scoped API tokens
Telegraf only needs to write to the telegraf bucket and Grafana only needs to read from it. Look up the bucket ID:
influx bucket list --name telegraf
ID Name Retention Shard group duration Organization ID Schema Type
a1b2c3d4e5f60718 telegraf 720h0m0s 24h0m0s 0f1e2d3c4b5a6978 implicit
Create a write-only token for Telegraf, replacing your_bucket_id with the ID above:
influx auth create --org cubepath --description "telegraf write" --write-bucket your_bucket_id
Then create a read-only token for Grafana:
influx auth create --org cubepath --description "grafana read" --read-bucket your_bucket_id
Each command prints a table with a Token column. Copy both tokens somewhere safe; you will use them in the next steps.
Step 4 - Installing and configuring Telegraf
Telegraf comes from the same repository:
sudo apt install telegraf
The package ships a very long example configuration that includes the legacy InfluxDB 1.x output. Move it aside and write a short configuration with only what you need:
sudo mv /etc/telegraf/telegraf.conf /etc/telegraf/telegraf.conf.orig
sudo nano /etc/telegraf/telegraf.conf
[agent]
interval = "10s"
round_interval = true
flush_interval = "10s"
omit_hostname = false
[[outputs.influxdb_v2]]
urls = ["http://127.0.0.1:8086"]
token = "${INFLUX_TOKEN}"
organization = "cubepath"
bucket = "telegraf"
[[inputs.cpu]]
percpu = true
totalcpu = true
report_active = true
[[inputs.mem]]
[[inputs.swap]]
[[inputs.system]]
[[inputs.processes]]
[[inputs.disk]]
ignore_fs = ["tmpfs", "devtmpfs", "devfs", "overlay", "squashfs"]
[[inputs.diskio]]
[[inputs.net]]
Each [[inputs.*]] block enables one plugin: CPU usage (with report_active adding a usage_active field), memory and swap, load average and uptime, process counts, filesystem usage and disk and network I/O. The token is not written in the file; Telegraf expands ${INFLUX_TOKEN} from its environment.
The Telegraf systemd unit reads environment variables from /etc/default/telegraf. Store the write token there and make the file readable only by root:
echo 'INFLUX_TOKEN=your_telegraf_write_token' | sudo tee /etc/default/telegraf > /dev/null
sudo chmod 600 /etc/default/telegraf
Before starting the service, run the inputs once in test mode. This prints the collected metrics in line protocol without sending them anywhere:
telegraf --config /etc/telegraf/telegraf.conf --test | head -n 3
> cpu,cpu=cpu0,host=tig-01 usage_active=2.4,usage_idle=97.6,usage_system=1.2,usage_user=1.1 1790245200000000000
> cpu,cpu=cpu-total,host=tig-01 usage_active=2.1,usage_idle=97.9,usage_system=1.0,usage_user=1.0 1790245200000000000
> disk,device=vda1,fstype=ext4,host=tig-01,mode=rw,path=/ free=17122394112i,total=20943937536i,used=3804766208i,used_percent=18.1 1790245200000000000
Start Telegraf and enable it at boot:
sudo systemctl enable --now telegraf
sudo systemctl restart telegraf
sudo systemctl status telegraf --no-pager
The restart makes sure the service reads the new configuration if the package had already started it. The status should be active (running), and sudo journalctl -u telegraf -n 20 should show no 401 Unauthorized or connection errors.
Step 5 - Verifying the data in InfluxDB
Wait about 30 seconds, then query the bucket with Flux to confirm that CPU points are arriving:
influx query 'from(bucket: "telegraf")
|> range(start: -5m)
|> filter(fn: (r) => r._measurement == "cpu" and r._field == "usage_active" and r.cpu == "cpu-total")
|> last()'
Result: _result
Table: keys: [_start, _stop, _field, _measurement, cpu, host]
_start:time _stop:time _field:string _measurement:string cpu:string host:string _time:time _value:float
------------------------------ ------------------------------ ---------------------- ---------------------- --------------------- --------------------- ------------------------------ ----------------------------
2026-09-24T10:40:12.000000000Z 2026-09-24T10:45:12.000000000Z usage_active cpu cpu-total tig-01 2026-09-24T10:45:10.000000000Z 2.08
A result with a recent _time means the Telegraf to InfluxDB half of the stack works.
Step 6 - Installing Grafana
Grafana is installed from Grafana Labs' APT repository. Add its key and the repository:
sudo wget -q -O /etc/apt/keyrings/grafana.asc https://apt.grafana.com/gpg.key
echo 'deb [signed-by=/etc/apt/keyrings/grafana.asc] https://apt.grafana.com stable main' | sudo tee /etc/apt/sources.list.d/grafana.list
sudo apt update
sudo apt install grafana
Enable and start the service, then allow its port through the firewall:
sudo systemctl enable --now grafana-server
sudo ufw allow 3000/tcp
Port 8086 stays closed in UFW, so InfluxDB is only reachable from the server itself. Confirm Grafana is listening:
sudo ss -tlnp | grep 3000
LISTEN 0 4096 *:3000 *:* users:(("grafana",pid=5123,fd=10))
Open http://your_server_ip:3000 in your browser, log in with admin / admin and set a new password when prompted.
Step 7 - Adding InfluxDB as a Grafana data source
You could add the data source in the web UI, but a provisioning file keeps it in version-controllable configuration and survives reinstalls. Create it:
sudo nano /etc/grafana/provisioning/datasources/influxdb.yaml
apiVersion: 1
datasources:
- name: InfluxDB
type: influxdb
access: proxy
url: http://127.0.0.1:8086
isDefault: true
jsonData:
version: Flux
organization: cubepath
defaultBucket: telegraf
secureJsonData:
token: your_grafana_read_token
The file contains a token, so make it readable only by root and the grafana group, then restart Grafana:
sudo chown root:grafana /etc/grafana/provisioning/datasources/influxdb.yaml
sudo chmod 640 /etc/grafana/provisioning/datasources/influxdb.yaml
sudo systemctl restart grafana-server
In Grafana, go to Connections > Data sources > InfluxDB and click Test at the bottom of the page. You should see a green message similar to datasource is working. 1 buckets found.
Step 8 - Building a dashboard panel
Create a dashboard with Dashboards > New > New dashboard > Add visualization and pick the InfluxDB data source. Switch the query editor to code and paste this Flux query, which plots total CPU usage per host:
from(bucket: "telegraf")
|> range(start: v.timeRangeStart, stop: v.timeRangeStop)
|> filter(fn: (r) => r._measurement == "cpu" and r._field == "usage_active" and r.cpu == "cpu-total")
|> aggregateWindow(every: v.windowPeriod, fn: mean, createEmpty: false)
v.timeRangeStart, v.timeRangeStop and v.windowPeriod are filled in by Grafana from the dashboard's time picker, so the panel resolution adapts when you zoom. Set the unit to Percent (0-100) under Standard options, give the panel a title and save the dashboard.
Add more panels the same way by changing the measurement and field, for example:
| Panel | _measurement | _field |
|---|---|---|
| Memory used % | mem | used_percent |
| Root disk used % | disk (add r.path == "/") | used_percent |
| Load average | system | load1 |
| Network received | net | bytes_recv (add derivative(unit: 1s, nonNegative: true)) |
Troubleshooting
- Telegraf logs
401 Unauthorized: the token in/etc/default/telegrafis wrong or lacks write permission on the bucket. Create a new one as in Step 3 and restart Telegraf. - Telegraf logs
bucket "telegraf" not found: theorganizationorbucketintelegraf.confdoes not match what you created withinflux setup. - Grafana test fails with
unauthorized: check the read token in the provisioning file and restartgrafana-server; provisioning files are read only at startup. - Panels show "No data": confirm the query works with
influx queryon the server, and check that the dashboard time range covers the period since Telegraf started.
Conclusion
You now have a working TIG stack on Ubuntu 24.04: Telegraf collects system metrics every 10 seconds, InfluxDB 2 stores them for 30 days in a dedicated bucket, and Grafana reads them with a read-only token to draw your dashboards. Next, you can install Telegraf on other servers and point them at this InfluxDB (opening port 8086 only to their IPs), add input plugins for Nginx, MySQL or Docker, or put Grafana behind an Nginx reverse proxy with HTTPS.
