If suricata is monitoring the wan interface, it doesn't see the scan when you do it from your lan. Different interface.
Emerging-scan.rules is one that has spotted ssh and nmap scans for me (I think).So you need to verify the rules you have enabled and the type of scan you are performing.A bit of backgound: https://forum.suricata.io/t/suricata-ids-and-nmap/506