Suricata rules about network scan

Hello Suricata Community!
I want to create a rule about network scan.This is my rule:
alert tcp any any -> any 22 (msg:"22 scan SYN"; flags:S; threshold: type both, track by_src, count 5, seconds 1; classtype:network-scan; sid:3000100; rev:1;)
I want to capture a source host send syn-pacp to five different destination hosts in a second,but my rule can not detect different destination hosts.
Are there any keywords that can solve this problem?

I don’t think you can easily check if one host has talked to multiple different hosts in the rule language.
Could probably be done using Lua, but I would rather see if there was a different approach I could take that would cater better to the Suriata rule language.