The scanning drop is an aggregation of the individual drop types, which includes ACL drop, Bad packet drop, Conn limit drop, icmp drop, inspect drop, interface drop, syn attack ....
Therefore, it will depend on your network traffic and there is no a recommended value for this.