How to Install InfluxDB on Ubuntu 26.04 (Step-by-Step)

How to Install InfluxDB on Ubuntu 26.04 LTS: Setup, Security, Telegraf & Grafana

InfluxDB is one of the most popular time series databases, built for data that arrives with a timestamp: server metrics, IoT sensor readings, application performance data and event logs. This guide installs InfluxDB on Ubuntu 26.04 LTS using the official InfluxData APT repository, walks through first-time setup, secures it with tokens and TLS, and connects it to Telegraf (data collection) and Grafana (dashboards).

Table of Contents

  1. Which InfluxDB Version Should You Install?
  2. Architecture of This Lab
  3. Prerequisites
  4. Step 1: Update the System
  5. Step 2: Add the InfluxData APT Repository
  6. Step 3: Install and Start InfluxDB
  7. Step 4: Initial Setup (User, Organization, Bucket, Token)
  8. Step 5: Write and Query Your First Data
  9. Step 6: Firewall Configuration
  10. Step 7: Enable HTTPS
  11. Step 8: Connect Telegraf and Grafana
  12. Alternative: InfluxDB 3 Core
  13. Backup and Restore
  14. Useful File Locations and Commands
  15. Troubleshooting
  16. FAQ
  17. Conclusion

1. Which InfluxDB Version Should You Install?

InfluxDB currently exists in two generations, and they are different products with different query languages and APIs. Pick the one that matches your goal before installing anything.

AspectInfluxDB 2.x (OSS)InfluxDB 3 Core
StatusMature, widely deployedNewer engine, evolving quickly
Storage engineTSM engineApache Arrow / Parquet based, object-store backed
Query languagesFlux and InfluxQLSQL and InfluxQL
Data modelOrganizations, bucketsDatabases, tables
Default port80868181
PackagingAPT package influxdb2Install script, tarball or Docker image
Web UIBuilt-inNot built in (use separate tooling)
Ecosystem maturityExtensive tutorials and integrationsGrowing
Choose it whenYou want a proven, well-documented setup with a UIYou prefer SQL and the newer architecture

This guide’s main path installs InfluxDB 2.x through APT because it is the most established route on Ubuntu. Section 12 covers InfluxDB 3 Core as an alternative.

2. Architecture of This Lab

  ┌───────────────┐   metrics    ┌──────────────────────────────────────────┐
  │ Servers, IoT, │ ───────────► │  Ubuntu 26.04 LTS                        │
  │ apps          │  (Telegraf)  │                                          │
  └───────────────┘              │   ┌──────────────┐    ┌───────────────┐  │
                                 │   │   Telegraf   │──► │   InfluxDB 2  │  │
  ┌───────────────┐              │   │  (collector) │    │   :8086       │  │
  │ Browser       │ ── HTTPS ──► │   └──────────────┘    │  bucket:      │  │
  │ (Influx UI)   │              │                       │  server_stats │  │
  └───────────────┘              │   ┌──────────────┐    └───────┬───────┘  │
                                 │   │   Grafana    │ ◄──────────┘          │
  ┌───────────────┐              │   │   :3000      │   Flux / InfluxQL      │
  │ Dashboards    │ ◄─────────── │   └──────────────┘                       │
  └───────────────┘              └──────────────────────────────────────────┘

3. Prerequisites

RequirementRecommendation
OSUbuntu 26.04 LTS (fresh or existing)
CPU / RAM2 vCPU and 4 GB RAM minimum for a lab; more RAM as series count grows
DiskSSD strongly recommended; plan for retention and growth
AccessA user with sudo privileges
NetworkOutbound HTTPS to repos.influxdata.com

Ubuntu 26.04 is the current LTS release. If a package or repository behaves unexpectedly on a brand new release, check the troubleshooting table in Section 15 first.

4. Step 1: Update the System

sudo apt update && sudo apt upgrade -y
sudo apt install -y curl gnupg ca-certificates

Set the correct timezone, because time series data depends on accurate clocks:

timedatectl status
sudo timedatectl set-timezone Asia/Jakarta     # adjust to your region
sudo timedatectl set-ntp true

5. Step 2: Add the InfluxData APT Repository

Download the signing key, verify its fingerprint, and store it in the keyring. The one-liner only writes the key if the fingerprint matches.

curl --silent --location -O https://repos.influxdata.com/influxdata-archive.key

gpg --show-keys --with-fingerprint --with-colons ./influxdata-archive.key 2>&1 \
  | grep -q '^fpr:\+24C975CBA61A024EE1B631787C3D57159FC2F927:$' \
  && cat influxdata-archive.key \
  | gpg --dearmor \
  | sudo tee /etc/apt/keyrings/influxdata-archive.gpg > /dev/null

Add the repository:

echo 'deb [signed-by=/etc/apt/keyrings/influxdata-archive.gpg] https://repos.influxdata.com/debian stable main' \
  | sudo tee /etc/apt/sources.list.d/influxdata.list

sudo apt update

Confirm the package is visible:

apt-cache policy influxdb2

If the fingerprint check fails, the key file was not written. Do not continue. Re-download the key and compare the fingerprint against InfluxData’s documentation, because the signing key has been rotated in the past.

6. Step 3: Install and Start InfluxDB

sudo apt install -y influxdb2 influxdb2-cli
  • influxdb2 is the server (influxd).
  • influxdb2-cli provides the influx command-line client.

Enable and start the service:

sudo systemctl enable --now influxdb
sudo systemctl status influxdb --no-pager

Check the health endpoint:

curl -s http://localhost:8086/health

Expected output (abridged):

{"name":"influxdb","message":"ready for queries and writes","status":"pass", ...}

7. Step 4: Initial Setup (User, Organization, Bucket, Token)

InfluxDB 2 organizes data as organization → bucket → measurement. A bucket is a named store with a retention policy, and an API token controls access. First-run setup creates the initial admin user, organization, bucket and operator token.

Option A: CLI setup (recommended for servers)

influx setup \
  --username admin \
  --password 'ChangeMe_UseALongPassword!' \
  --org bckinfo \
  --bucket server_stats \
  --retention 30d \
  --force

The command prints the details and stores an active configuration profile for the influx CLI. The token is saved to ~/.influxdbv2/configs. Confirm it:

influx config list

Option B: Web UI

Open http://<server-ip>:8086 in a browser, click Get Started, and fill in the same values.

Create a least-privilege token

Avoid using the operator token for applications. Create a token scoped to a single bucket:

influx bucket list                                   # note the bucket ID
influx auth create \
  --org bckinfo \
  --description "telegraf-write" \
  --write-bucket <BUCKET_ID>

Store each token in a secrets manager or a root-only file. It cannot be recovered in full after you leave the screen in some workflows, so save it immediately.

8. Step 5: Write and Query Your First Data

InfluxDB ingests line protocol: measurement,tag=value field=value timestamp.

influx write \
  --bucket server_stats \
  --org bckinfo \
  --precision s \
  'cpu,host=web01,region=jkt usage=42.5'

Write a few more points, then query them with Flux:

influx query --org bckinfo '
from(bucket: "server_stats")
  |> range(start: -1h)
  |> filter(fn: (r) => r._measurement == "cpu")
'

Or open Data Explorer in the web UI to build the same query visually.

ConceptMeaningExample
MeasurementLike a table namecpu
TagIndexed metadata, string valueshost=web01
FieldThe actual measured values, not indexedusage=42.5
TimestampWhen the reading happenednanoseconds since epoch

Design tip: put values you filter or group by (host, region) in tags, and the numbers you measure in fields. Very high-cardinality tags such as unique request IDs can hurt performance.

9. Step 6: Firewall Configuration

If you only use InfluxDB locally, no firewall change is needed. To accept remote writes and UI access, allow port 8086 from trusted addresses only.

sudo ufw allow OpenSSH
sudo ufw allow from 10.10.10.0/24 to any port 8086 proto tcp
sudo ufw enable
sudo ufw status numbered

By default influxd listens on all interfaces at :8086. To restrict it to localhost (for example, when a reverse proxy sits in front), set the bind address in the config file in the next step.

10. Step 7: Enable HTTPS

Never send tokens over plain HTTP across a network. For a lab you can generate a self-signed certificate; for production use a certificate from your CA or Let’s Encrypt.

sudo mkdir -p /etc/influxdb/tls
sudo openssl req -x509 -nodes -newkey rsa:4096 -days 365 \
  -keyout /etc/influxdb/tls/influxdb.key \
  -out /etc/influxdb/tls/influxdb.crt \
  -subj "/CN=influx.example.local"

sudo chown influxdb:influxdb /etc/influxdb/tls/influxdb.*
sudo chmod 600 /etc/influxdb/tls/influxdb.key

Create or edit /etc/influxdb/config.toml:

http-bind-address = ":8086"
tls-cert = "/etc/influxdb/tls/influxdb.crt"
tls-key  = "/etc/influxdb/tls/influxdb.key"

Restart and test:

sudo systemctl restart influxdb
curl -k https://localhost:8086/health

Update the CLI profile so it uses HTTPS (add --skip-verify only for self-signed lab certificates):

influx config set --active --host-url https://localhost:8086

11. Step 8: Connect Telegraf and Grafana

Telegraf (collect system metrics)

Telegraf comes from the same repository:

sudo apt install -y telegraf

Edit /etc/telegraf/telegraf.conf (or a file in /etc/telegraf/telegraf.d/):

[[outputs.influxdb_v2]]
  urls = ["https://localhost:8086"]
  token = "$INFLUX_TOKEN"
  organization = "bckinfo"
  bucket = "server_stats"
  insecure_skip_verify = true      # lab only, remove when using a trusted certificate

[[inputs.cpu]]
  percpu = true
  totalcpu = true
[[inputs.mem]]
[[inputs.disk]]
  ignore_fs = ["tmpfs", "devtmpfs", "overlay"]
[[inputs.net]]

Provide the token through an environment file rather than hard-coding it:

echo 'INFLUX_TOKEN=<your-write-token>' | sudo tee /etc/default/telegraf
sudo chmod 600 /etc/default/telegraf
sudo systemctl enable --now telegraf
sudo journalctl -u telegraf -n 20 --no-pager

Grafana (dashboards)

Install Grafana from its official repository (see Grafana’s documentation for the current repository instructions), then add a data source:

SettingValue
TypeInfluxDB
Query languageFlux
URLhttps://localhost:8086
Organizationbckinfo
TokenA read-only token for the bucket
Default bucketserver_stats

Create a read-only token for Grafana:

influx auth create --org bckinfo --description "grafana-read" --read-bucket <BUCKET_ID>

12. Alternative: InfluxDB 3 Core

If you prefer SQL and the newer engine, InfluxDB 3 Core runs as a single binary. The project is evolving fast, so treat the commands below as a starting point and confirm them against InfluxData’s current documentation.

Docker method (requires Docker; see Docker on Ubuntu 26.04 (verify slug)):

docker run -d --name influxdb3 --restart unless-stopped \
  -p 8181:8181 \
  -v influxdb3_data:/var/lib/influxdb3 \
  influxdb:3-core \
  influxdb3 serve \
    --node-id node0 \
    --object-store file \
    --data-dir /var/lib/influxdb3

Script method:

curl -O https://www.influxdata.com/d/install_influxdb3.sh
less install_influxdb3.sh        # always review a script before running it
sh install_influxdb3.sh

Typical first steps afterwards:

influxdb3 create token --admin                        # save the printed token
influxdb3 write --database sensors --token "$TOKEN" 'home,room=kitchen temp=22.1'
influxdb3 query --database sensors --token "$TOKEN" "SELECT * FROM home"

Note that InfluxDB 3 Core listens on port 8181 by default, has no built-in web UI, and uses different tokens, databases and query semantics from InfluxDB 2. Do not mix the two sets of tooling.

13. Backup and Restore

InfluxDB 2 includes a backup command that works against a running server.

sudo mkdir -p /backup/influxdb
influx backup /backup/influxdb/$(date +%F) --token "$INFLUX_OPERATOR_TOKEN"

Restore into a fresh bucket or instance:

influx restore /backup/influxdb/2026-09-21 --token "$INFLUX_OPERATOR_TOKEN"

Schedule a nightly backup with cron and copy it off the host:

sudo tee /etc/cron.d/influxdb-backup > /dev/null <<'EOF'
0 2 * * * root influx backup /backup/influxdb/$(date +\%F) --token "$(cat /root/.influx_token)" && find /backup/influxdb -mtime +7 -type d -exec rm -rf {} +
EOF

Also set sensible retention periods on buckets. Data that is never deleted is the most common reason a time series database fills its disk.

influx bucket update --id <BUCKET_ID> --retention 90d

14. Useful File Locations and Commands

ItemLocation or command
Config file/etc/influxdb/config.toml
Data directory/var/lib/influxdb/
CLI profiles~/.influxdbv2/configs
Service logssudo journalctl -u influxdb -f
Service control`sudo systemctl status
List bucketsinflux bucket list
List tokensinflux auth list
Server versioninfluxd version
Health checkcurl -s http://localhost:8086/health

15. Troubleshooting

SymptomLikely causeFix
E: Unable to locate package influxdb2Repository not added or apt update not runRecheck /etc/apt/sources.list.d/influxdata.list, then sudo apt update
NO_PUBKEY or signature error on apt updateKey missing, wrong path or outdatedRe-download influxdata-archive.key, verify the fingerprint, rewrite /etc/apt/keyrings/influxdata-archive.gpg
Installed an old influxdb package (1.x)The distribution package name differs from influxdb2Remove it and install influxdb2 from the InfluxData repository
Repository has no packages for the releaseVendor repo lagging on a brand new Ubuntu releaseConfirm the stable main line is used (not the codename), or install the .deb from InfluxData’s download page, or use Docker
influx setup says the instance is already set upInitial setup was already completed in the UIUse existing credentials, or create a new user with influx user create
curl: (7) Failed to connect to localhost:8086Service not running or crashedsudo systemctl status influxdb and journalctl -u influxdb -n 50
Service fails after editing config.tomlSyntax error or unreadable certificateValidate the TOML; check ownership influxdb:influxdb and mode on cert and key
401 unauthorizedMissing, wrong or insufficient tokenCheck influx auth list; use a token with the required read or write permission
x509: certificate signed by unknown authoritySelf-signed certificateUse --skip-verify for labs only, or install a trusted certificate
Remote clients cannot connectFirewall or bind addressAllow port 8086 in ufw from the client subnet; confirm the server is not bound to localhost only
Disk usage keeps growingNo retention on the bucketSet --retention on the bucket and confirm old shards are being dropped
Slow queries and high memoryHigh-cardinality tagsMove unique values into fields; review the tag design

16. FAQ

Is InfluxDB free?
InfluxDB 2 OSS and InfluxDB 3 Core are open source. InfluxData also offers commercial editions and a managed cloud with additional features such as clustering and enterprise support.

Should I use InfluxDB 2 or InfluxDB 3?
Choose InfluxDB 2 if you want the most mature ecosystem, a built-in UI and Flux. Choose InfluxDB 3 Core if you prefer SQL and are comfortable with a younger, fast-changing product.

How is InfluxDB different from Prometheus?
Prometheus pulls metrics and is designed mainly for monitoring and alerting. InfluxDB accepts pushed data, supports richer general-purpose time series storage, and suits IoT and event data as well as infrastructure metrics.

Can I run InfluxDB in Docker instead?
Yes. The official images exist for both InfluxDB 2 and 3. APT is simpler for a single dedicated server, while Docker fits containerized stacks.

How much RAM does InfluxDB need?
It depends mostly on the number of unique series (cardinality) and query load. Start with 4 GB for a lab and monitor memory as you add data.

How do I upgrade InfluxDB?
Run sudo apt update && sudo apt install --only-upgrade influxdb2 influxdb2-cli, and take a backup first.

17. Conclusion

You now have InfluxDB 2 running on Ubuntu 26.04 with a secured initial setup, scoped API tokens, HTTPS, Telegraf collecting metrics, Grafana ready for dashboards and a backup routine. From here, the highest-value next steps are defining retention policies per bucket, designing tags carefully to keep cardinality under control, and adding alerting.

(Visited 25 times, 1 visits today)

You may also like